CVE-2024-28072: SolarWinds Serv-U

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.

Affected products

  • SolarWinds Serv-U: before 15.4.2 (fixed in 15.4.2); version 15.4.2 only

Published 2024-05-03. Last modified 2026-06-17.