Solarwinds

Serv-u

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.33%
  • Veröffentlicht 16.10.2024 08:15:06
  • Zuletzt bearbeitet 17.10.2024 20:17:29

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when softwar...

Warnung Medienbericht
  • EPSS 99.61%
  • Veröffentlicht 06.06.2024 09:15:14
  • Zuletzt bearbeitet 26.02.2026 15:04:20

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

  • EPSS 0.64%
  • Veröffentlicht 03.05.2024 08:15:07
  • Zuletzt bearbeitet 25.02.2025 17:12:45

A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.

  • EPSS 1.12%
  • Veröffentlicht 17.04.2024 17:15:14
  • Zuletzt bearbeitet 10.02.2025 22:38:47

SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.

  • EPSS 0.83%
  • Veröffentlicht 06.12.2023 04:15:07
  • Zuletzt bearbeitet 21.11.2024 08:18:36

A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.

  • EPSS 0.87%
  • Veröffentlicht 07.09.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:37

A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4.  So...

  • EPSS 0.92%
  • Veröffentlicht 11.08.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 08:08:06

A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 

  • EPSS 0.46%
  • Veröffentlicht 15.06.2023 22:15:09
  • Zuletzt bearbeitet 25.02.2026 17:18:56

SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the request discloses sensitive data.

  • EPSS 0.69%
  • Veröffentlicht 16.12.2022 16:15:22
  • Zuletzt bearbeitet 25.02.2026 16:20:46

This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

  • EPSS 0.52%
  • Veröffentlicht 16.12.2022 16:15:16
  • Zuletzt bearbeitet 21.11.2024 06:12:09

Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.