CVE-2024-45711: SolarWinds Serv-U
High severity, CVSS 8.8. EPSS: 6.3% chance of exploitation in the next 30 days.
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are abused. Authentication is required for this vulnerability
Affected products
- SolarWinds Serv-U: before 15.5 (fixed in 15.5)
Published 2024-10-16. Last modified 2026-06-17.