Documentation forServ-U MFT & Serv-U FTP Server

Serv-U File Server 15.3 Release Notes

Release date: January 19, 2022

These release notes describe the new features, improvements, and fixed issues in SolarWinds Serv-U File Server 15.3. They also provide information about upgrades and describe workarounds for known issues.

If you are looking for previous release notes for Serv-U File Server, see Previous Version documentation.

For details about the latest hotfixes, see Serv-U hotfixes.

Additional Serv-U documentation includes:

New features and improvements

Serv-U File Server 15.3 introduces the new Serv-U Web Client, which features:

  • Update to modern UI without installing Java
  • Drag and drop support for uploads
  • Multiple file and folder upload / zip download
  • New UI for File sharing (MFT only)
  • Option to use new or legacy web client
  • Security and stability improvements

For improved security, SHA256 is now used as the default setting for creating certificates.

The new documentation for the new web client can be found online and in the Administrator Guide.


Upgrade notes

Licensing

The Serv-U licensing framework has been updated since Serv-U 15.2.3 and a new license key now needs to be used to activate this product version.

If your Serv-U product maintenance is active, you can find your new license key generated on customer portal. Use this new license key to activate Serv-U after installation.

Solarwinds strongly recommend that you upgrade to this version with the new licensing framework as older framework will not be supported in the future.

Password security

If you are upgrading from version 15.1.7 or older, increased password security and automatically converts existing MD5 passwords using a more secure algorithm when users connect for the first time after upgrade.

If an account is not used within 90 days of the upgrade, access will be restricted and the user will not be able to log in afterward. The administrator will be required to change their password.


CVE fixed issues

SolarWinds would like to thank our Security Researchers below for reporting on this issue in a responsible manner and working with our security, product, and engineering teams to fix the vulnerability.

CVE-ID Vulnerability Title Description Severity Credit
CVE-2021-35247 Improper Input Validation Vulnerability

The Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization.

Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters

4.3 Medium Jonathan Bar Or of Microsoft (@yo_yo_yo_jbo)

Deprecation notices

In Serv-U 15.3, the following platforms and features are deprecated.

Deprecated platforms and features are still supported in the current release. However, they will be unsupported in future release. Plan on upgrading deprecated platforms, and avoid using deprecated features. Customizations applied to a deprecated feature might not be migrated if a new feature replaces the deprecated one.

For information about supported version of SolarWinds products, see Currently supported software versions.

Deprecations
Java-based Serv-U web client modules FTP Voyager JV and Web Client Pro will be replaced by new Serv-U web client in next version. These modules are still available in version 15.3 together with new Serv-U web client to support migration path.
TLS 1.1 and older will be removed from the product.

Legal notices

© 2022 SolarWinds Worldwide, LLC. All rights reserved.

This document may not be reproduced by any means nor modified, decompiled, disassembled, published or distributed, in whole or in part, or translated to any electronic medium or other means without the prior written consent of SolarWinds. All right, title, and interest in and to the software, services, and documentation are and shall remain the exclusive property of SolarWinds, its affiliates, and/or its respective licensors.

SOLARWINDS DISCLAIMS ALL WARRANTIES, CONDITIONS, OR OTHER TERMS, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, ON THE DOCUMENTATION, INCLUDING WITHOUT LIMITATION NONINFRINGEMENT, ACCURACY, COMPLETENESS, OR USEFULNESS OF ANY INFORMATION CONTAINED HEREIN. IN NO EVENT SHALL SOLARWINDS, ITS SUPPLIERS, NOR ITS LICENSORS BE LIABLE FOR ANY DAMAGES, WHETHER ARISING IN TORT, CONTRACT OR ANY OTHER LEGAL THEORY, EVEN IF SOLARWINDS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

The SolarWinds, SolarWinds & Design, Orion, and THWACK trademarks are the exclusive property of SolarWinds Worldwide, LLC or its affiliates, are registered with the U.S. Patent and Trademark Office, and may be registered or pending registration in other countries. All other SolarWinds trademarks, service marks, and logos may be common law marks or are registered or pending registration. All other trademarks mentioned herein are used for identification purposes only and are trademarks of (and may be registered trademarks) of their respective companies.