Tools

Serv-U 15.4.0 Hotfix 2

Describes the fixes in Serv-U 15.4.0 Hotfix 2, and provides instructions for installing and uninstalling the hotfix.

First published date

8/30/2023 11:01 AM

Last published date

8/30/2023 1:46 PM

Overview

This SolarWinds hotfix addresses the following issues:

  • Unable to change password 
  • Serv-U crashes during SFTP user authentication
  • DB user schema should not contain MFA related fields
  • Serv-U MFA can be bypassed

SolarWinds CVEs

CVE-IDVulnerability TitleDescriptionSeverity
CVE-2023-400602FA/MFA Bypass Vulnerability in Serv-U 15.4 and Serv-U 15.4 Hotfix 1A vulnerability has been identified within Serv-U 15.4 and Serv-U 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. The previous vulnerability (CVE-2023-35179) was not completely resolved in 15.4 Hotfix 1.
6.6 Medium

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution

Requirements

This hotfix is suitable for both Windows and Linux OSs, 32-bit and 64-bit. It requires either Serv-U 15.4.0.147 or Serv-U 15.4.0.172 Hotfix 1.

Installation instructions

This hotfix contains the following files and folders required to upgrade your installation:

Windows OS:

  • Serv-U.exe
  • Serv-U-Tray.exe
  • Serv-U.dll
  • Serv-U-RES.dll
  • RhinoNET.dll
  • RhinoRES.dll
  • Client/

Linux OS:

  • Serv-U
  • Client/

In the following procedures, the default installation directory <Serv-U-InstallDir> is:

Windows OS:

       C:\Program Files\RhinoSoft\Serv-U

Linux OS:

       /usr/local/Serv-U

Install the hotfix

  1. Shut down all running Serv-U processes: 
    1. Right-click the tray icon and select Stop Serv-U.
    2. Right-click the tray icon and select Exit Tray.
  2. Back up the following files and folders:
    • Windows OS:
      • <Serv-U-InstallDir>\Serv-U.exe
      • <Serv-U-InstallDir>\Serv-U-Tray.exe
      • <Serv-U-InstallDir>\Serv-U.dll
      • <Serv-U-InstallDir>\Serv-U-RES.dll
      • <Serv-U-InstallDir>\RhinoNET.dll
      • <Serv-U-InstallDir>\RhinoRES.dll
      • <Serv-U-InstallDir>\Client\
    •    Linux OS:
      • <Serv-U-InstallDir>/Serv-U
      • <Serv-U-InstallDir>/Client/
  3. Extract the hotfix archive to a temporary location. 
  4. Open the folder for the platform on which Serv-U is installed.
    For example, open the Linux/64-bit folder if Serv-U is installed on a 64-bit version of Linux.
  5. On Linux, modify the permissions of the file by executing the following command:
    chmod u+xs Serv-U
  6. Copy the contents of this folder to your Serv-U installation directory.
  7. Start the Serv-U-Tray application.
  8. Right-click the Serv-U tray icon and select Start Serv-U.
    The hotfix is installed.

Result

The issues listed at the top of the page are resolved.

Uninstall

  1. Shut down all running Serv-U processes. 
    1. Right-click the tray icon and select Stop Serv-U.
    2. Right-click the tray icon and select Exit Tray.
  2. Replace the following files and folders with the ones you backed up during installation: 
    • Windows OS:
      • <Serv-U-InstallDir>\Serv-U.exe
      • <Serv-U-InstallDir>\Serv-U-Tray.exe
      • <Serv-U-InstallDir>\Serv-U.dll
      • <Serv-U-InstallDir>\Serv-U-RES.dll
      • <Serv-U-InstallDir>\RhinoNET.dll
      • <Serv-U-InstallDir>\RhinoRES.dll
      • <Serv-U-InstallDir>\Client\
    • Linux OS:
      • <Serv-U-InstallDir>/Serv-U
      • <Serv-U-InstallDir>/Client/
  3. Start the Serv-U-Tray application.
  4. Right-click the Serv-U tray icon and select Start Serv-U.
    The hotfix is uninstalled.

For more information, contact Technical Support at https://www.serv-u.com/support .