Tools

Serv-U MFT Server vulnerability: Directory Transversal Vulnerability in Serv-U 15.3 (CVE-2022-35250)

This article describes the steps to address the vulnerability in Serv-U about Directory Transversal Vulnerability in Serv-U 15.3 (CVE-2022-35250)

First published date

3/3/2022 1:38 AM

Last published date

3/3/2022 1:47 AM

Overview

An external security researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. If exploited, this vulnerability could allow access to files relating to the Serv-U installation and server files. It is important to note no exploits of this vulnerability have been reported in the wild.

The only affected version is the Serv-U MFT 15.3 Base Version. The Serv-U Gateway Application is NOT affected by this Vulnerability.

For more detailed information, please visit this Solarwinds Security Advisory:
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35250

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Cause

Product Vulnerability.

Resolution

 To remediate this vulnerability, we encourage all customers running on the version 15.3 upgrade to apply the Serv-U 15.3 Hotfix 1.