CVE-2022-38106: Cross-Site Scripting Vulnerability in Serv-U Web Client
Published Dec 16, 2022
·Updated
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.
Affected Software
2 affected components
SolarWinds Serv-U=15.3.0
SolarWinds Serv-U=15.3.1
Remediation
Information
SolarWinds advises to upgrade to the latest version of Serv-U File Server 15.3.2 once became generally available.
Event History
Dec 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-38106.
2
What is the severity of CVE-2022-38106?
The severity of CVE-2022-38106 is medium (5.4).
3
Which versions of SolarWinds Serv-U are affected by CVE-2022-38106?
The versions 15.3.0 and 15.3.1 of SolarWinds Serv-U are affected by CVE-2022-38106.
4
What is the CWE number for CVE-2022-38106?
The CWE number for CVE-2022-38106 is CWE-79.
5
How can I fix the vulnerability CVE-2022-38106?
To fix CVE-2022-38106, update your SolarWinds Serv-U software to version 15.3.2 or higher.