What happened
SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.
Affected versions
Serv-U: 15.4.2 HF 1 and previous versions; 0 through 15.4.2_hf_1 (custom) Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
Source timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
CVE record published by NVDView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.