CISA Known Exploited Vulnerability (KEV)
SolarWinds Serv-U Path Traversal Vulnerability
July 17, 2024
August 7, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-22 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) |