CVE-2020-35211
Java vulnerability analysis and mitigation

Overview

SolarWinds Serv-U contains a critical memory escape vulnerability (CVE-2021-35211) that allows remote code execution. The vulnerability was discovered in July 2021 and affects the SSH component of Serv-U, which is used for secure file transfers using SCP. This vulnerability was reported to SolarWinds by Microsoft and has been actively exploited in the wild (Censys Report).

Technical details

The vulnerability exists in the SSH component of Serv-U and involves a memory escape condition that can lead to remote code execution. According to analysis, over 8,300 SolarWinds SSH services were found exposed to the internet, with significant presence in China and the US. The vulnerability has been assigned CWE-787 classification relating to memory corruption (CISA KEV).

Impact

If Serv-U's SSH is exposed to the internet, successful exploitation would give attackers the ability to remotely run arbitrary code with privileges. This access allows attackers to perform malicious actions such as installing and running malicious payloads, or viewing and modifying data (Censys Report).

Mitigation and workarounds

SolarWinds has released hotfix 15.2.3 HF2 to address this vulnerability. Organizations are advised to either apply this hotfix or block internet access to mitigate CVE-2021-35211. Additionally, it is recommended to perform forensic analysis on any Serv-U host that has exposed SSH to the internet (Censys Report).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-26866HIGH8.8
  • JavaJava
  • org.apache.hugegraph:hg-pd-core
NoYesDec 12, 2025
CVE-2025-66474HIGH8.7
  • JavaJava
  • org.xwiki.rendering:xwiki-rendering-xml
NoYesDec 10, 2025
CVE-2025-66473HIGH8.7
  • JavaJava
  • org.xwiki.platform:xwiki-platform-rest-server
NoYesDec 10, 2025
CVE-2025-67505HIGH8.4
  • JavaJava
  • com.okta.sdk:okta-sdk-root
NoYesDec 10, 2025
CVE-2025-14518MEDIUM5.3
  • JavaJava
  • tech.powerjob:powerjob-common
NoNoDec 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management