CISA Known Exploited Vulnerability

CVE-2021-35247

SolarWinds · Serv-U

SolarWinds Serv-U Improper Input Validation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

Required action

Apply updates per vendor instructions.