Generated remediation guidance and an executive summary. No account required.
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
Use CWE-20, Solarwinds vendor hub and Serv-U product page to widen CVE-2021-35247 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-28995, CVE-2025-40541 and CVE-2025-40540 for nearby disclosures in the same product family.