A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
References
Configurations
Configuration 1 (hide)
|
History
25 Feb 2025, 17:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US - Release Notes | |
References | () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072 - Vendor Advisory | |
CPE | cpe:2.3:a:solarwinds:serv-u:15.4.2:-:*:*:*:*:*:* cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo | |
First Time |
Solarwinds serv-u
Solarwinds |
Information
Published : 2024-05-03 08:15
Updated : 2025-02-25 17:12
NVD link : CVE-2024-28072
Mitre link : CVE-2024-28072
CVE.ORG link : CVE-2024-28072
JSON object : View
Products Affected
solarwinds
- serv-u
CWE