CVE-2024-28072: SolarWinds Serv-U
Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
Affected products
- SolarWinds Serv-U: before 15.4.2 (fixed in 15.4.2); version 15.4.2 only
Published 2024-05-03. Last modified 2026-06-17.