QID 379141

Date Published: 2024-01-22

QID 379141: SolarWinds Serv-U HTML Injection Vulnerability

SolarWinds Serv-U Managed File Transfer Server is a versatile, easy-to-deploy solution that integrates well into existing infrastructure. It allows us to meet all our compliance requirements and ensures peace of mind for file transfers.

Affected versions:
Serv-U 15.4 HF2 and earlier

QID Detection Logic(Authenticated):
This QID checks for the vulnerable version of Serv-U on windows OS

QID Detection Logic(UnAuthenticated):
This QID checks the banner to detect if the device is running vulnerable SolarWinds Serv-U version.

Successful exploit impacts intergity

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    For more information about patch and fixes visit Serv-U 15.4 Security Advisory.
    Software Advisories
    Advisory ID Software Component Link
    Serv-U URL Logo documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-4-1_release_notes.htm#link3