Executive brief
The SolarWinds Serv-U web login screen failed to sufficiently sanitize characters used in LDAP authentication. This improper input validation allowed attackers to build and send unsanitized queries, though the vendor noted that many LDAP servers ignored the improper characters.
Affected products
- SolarWinds Serv-U <= 15.2.5
Timeline
- 2022-01-18: disclosed: Initial disclosure by SolarWinds regarding LDAP input validation improvements.
- 2022-01-21: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2022-01-21: advisory: NVD publication date.
- 2022-01-21: exploited: Reported as exploited in the wild.