Show filters
291 Total Results
Displaying 11-20 of 291
Sort by:
Attacker Value
Unknown
CVE-2021-31474
Disclosure Date: May 21, 2021 (last updated November 28, 2024)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12213.
1
Attacker Value
Unknown
CVE-2023-35187
Disclosure Date: October 19, 2023 (last updated October 26, 2023)
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated user to achieve the Remote Code Execution.
1
Attacker Value
Unknown
CVE-2023-35185
Disclosure Date: October 19, 2023 (last updated December 29, 2023)
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileges.
1
Attacker Value
Unknown
CVE-2023-35182
Disclosure Date: October 19, 2023 (last updated October 26, 2023)
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server.
1
Attacker Value
Unknown
CVE-2022-47505
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.
1
Attacker Value
Unknown
CVE-2023-23839
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information.
1
Attacker Value
Unknown
CVE-2022-47509
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.
1
Attacker Value
Unknown
SolarWinds Orion Platform Reverse Tabnabbing and Open Redirect — CVE-2021-3109
Disclosure Date: March 26, 2021 (last updated November 28, 2024)
The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context of an administrator account.
1
Attacker Value
Unknown
SolarWinds Orion Platform Stored XSS in Customize view —CVE-2020-35856
Disclosure Date: March 26, 2021 (last updated November 28, 2024)
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
1
Attacker Value
Unknown
CVE-2021-25275
Disclosure Date: February 03, 2021 (last updated November 28, 2024)
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected by SolarWinds applications, and leads to admin access to the applications by inserting or changing authentication data stored in the Accounts table of the database.
1