solarwinds serv-u CVE-2018-10240 is a vulnerability in SolarWinds Serv U
Published on May 16, 2018

SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.

NVD


Products Associated with CVE-2018-10240

Want to know whenever a new CVE is published for SolarWinds Serv U? stack.watch will email you.

 

Exploit Probability

EPSS
1.36%
Percentile
79.96%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.