Tools
Serv-U 15.4.2 Hotfix 2 Release Notes
This article provides an overview of Serv-U 15.4.2 Hotfix 2, released on June 5, 2024, and provides instructions for installing and uninstalling the hotfix.
First published date
Last published date
Overview
Recommended Installation or Upgrade Path
This hotfix requires that Serv-U 15.4.2 be installed. It addresses the following issue:
- Directory transversal vulnerability
SolarWinds CVEs
SolarWinds would like to thank our Security Researchers below for reporting on the issue in a responsible manner and working with our security, product, and engineering teams to fix the vulnerability.
|
CVE-ID |
Vulnerability Title |
Description |
Severity | Credit |
|
CVE-2024-28995 |
SolarWinds Serv-U Directory Transversal Vulnerability |
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. |
8.6 High | Hussein Daher |
Product section
Resolution
Environment:
Requirements
Important! If anonymous user is used, please refer to the Frequently Asked Questions section before upgrading.
This hotfix is suitable for both Windows and Linux OSs, 32-bit and 64-bit. It requires Serv-U 15.4.2.
Installation instructions
This hotfix is available for download by logging into the Customer Portal and navigating to the Downloads page, then selecting your product and license.
This hotfix contains the following files and folders required to upgrade your installation:
-
In Windows OS:
- Serv-U.exe
- Serv-U-Tray.exe
- Serv-U.dll
- Serv-U-RES.dll
- RhinoNET.dll
- RhinoRES.dll
- Client\Common\Scripts\functions.js
- Client\WebClientNew\
- In Linux OS:
- Serv-U
- Client/Common/Scripts/functions.js
- Client/WebClientNew/
In the following procedures, the default installation directory <Serv-U-InstallDir> is:
- In Windows OS
-
C:\Program Files\RhinoSoft\Serv-U
-
- In Linux OS:
-
/usr/local/Serv-U
-
Install the hotfix
-
Shut down all running Serv-U processes.
-
Right-click the tray icon and select Stop Serv-U.
-
Right-click the tray icon and select Exit Tray.
-
Back up the following files and folders:
-
In Windows OS:
- <Serv-U-InstallDir>\Serv-U.exe
- <Serv-U-InstallDir>\Serv-U-Tray.exe
- <Serv-U-InstallDir>\Serv-U.dll
- <Serv-U-InstallDir>\Serv-U-RES.dll
- <Serv-U-InstallDir>\RhinoNET.dll
- <Serv-U-InstallDir>\RhinoRES.dll
- <Serv-U-InstallDir>\Client\Common\Scripts\functions.js
- <Serv-U-InstallDir>\Client\WebClientNew\
Note: Replace all files in the Client directory. If functions.js is not update, end user cannot login properly.
-
In Linux OS:
- <Serv-U-InstallDir>/Serv-U
- <Serv-U-InstallDir>/Client/Common/Scripts/functions.js
- <Serv-U-InstallDir>/Client/WebClientNew/
Note: Replace all files in the Client directory. If functions.js is not update, end user cannot login properly.
-
Extract the hotfix archive to a temporary location.
-
Open the folder for the platform on which Serv-U is installed.
For example, open the Linux/64-bit folder if Serv-U is installed on a 64-bit version of Linux.
-
On Linux, modify the permissions of the file by executing the following command:
chmod u+xs Serv-U
-
Copy the contents of this folder to your Serv-U installation directory.
-
Start the Serv-U Tray application.
-
Right-click the Serv-U Tray icon and select Start Serv-U.
The hotfix is installed.
Result
The issue listed at the top of the page is resolved.
Uninstall the hotfix
-
Shut down all running Serv-U processes.
-
Right-click the tray icon and select Stop Serv-U.
-
Right-click the tray icon and select Exit Tray.
-
Replace the following files and folders with the ones you backed up during installation:
-
In Windows OS:
- <Serv-U-InstallDir>\Serv-U.exe
- <Serv-U-InstallDir>\Serv-U-Tray.exe
- <Serv-U-InstallDir>\Serv-U.dll
- <Serv-U-InstallDir>\Serv-U-RES.dll
- <Serv-U-InstallDir>\RhinoNET.dll
- <Serv-U-InstallDir>\RhinoRES.dll
- <Serv-U-InstallDir>\Client\Common\Scripts\functions.js
- <Serv-U-InstallDir>\Client\WebClientNew\
-
In Linux OS:
- <Serv-U-InstallDir>/Serv-U
- <Serv-U-InstallDir>/Client/Common/Scripts/functions.js
- <Serv-U-InstallDir>/Client/WebClientNew/
-
Start the Serv-U Tray application.
Right-click the Serv-U application.
The hotfix is uninstalled.
Frequently Asked Questions
For customers upgrading from Serv-U 15.3.1 and below, please read carefully.
- Due to changes in Serv-U 15.3.2 related to transition to Network Service from Local System , the Serv-U license will need to be re-apply using the following instruction .
After upgrading to Serv-U 15.4.2 HF1 / HF2, end user cannot login. If they hit the refresh button, then login is successful.
- This issue has been identified as Serv-U 15.4.2 HF1 or HF2 was applied to a different Serv-U base version. For more information, refer to "Error: Operation was not successful, a parameter was invalid" when logging in via web client after applying Serv-U 15.4.2 HF1 or HF2
Does the Serv-U 15.4.2 apply to Serv-U Gateway?
- No, Serv-U 15.4.2 Hotfix 1 and Hotfix 2 should only be applied inside the Serv-U MFT server. The Serv-U Gateway application does not need any hotfixes applied
Can the Serv-U 15.4.2 HF2 applied to other server versions other than Serv-U 15.4.2?
- No. If a hotfix is already applied while on an older version, upgrade to version 15.4.2 first, then proceed to apply hotfix 2.
Do I need to apply Serv-U 15.4.2 HF1 before applying HF2?
- No. As of June 25th, the instructions were updated. All previous changes in HF1 are included in HF2.
After upgrading to Serv-U 15.4.2 HF2, anonymous login in longer works. What do I do to get anonymous user to work again?
- Starting in the later version, anonymous user requires a password. For instructions how to set a password, please refer to Configure Anonymous Access In Serv-U.
For Serv-U 15.4.2 Troubleshooting Guide, please refer to the following article.
For more information, contact Technical Support at https://serv-u.com/support.