Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown

CVE-2023-33229

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML.
Attacker Value
Unknown

CVE-2023-33225

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
Attacker Value
Unknown

CVE-2023-33224

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
Attacker Value
Unknown

CVE-2023-23844

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
Attacker Value
Unknown

CVE-2023-23843

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
Attacker Value
Unknown

CVE-2022-47512

Disclosure Date: December 15, 2022 (last updated September 17, 2024)
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected
Attacker Value
Unknown

CVE-2022-36965

Disclosure Date: September 28, 2022 (last updated September 17, 2024)
Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).