CVE-2024-45711

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
16/10/2024
Last modified:
17/10/2024

Description

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are abused. Authentication is required for this vulnerability

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* 15.5 (excluding)