Filtered by vendor Solarwinds
Subscribe
Total
314 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-17127 | 1 Solarwinds | 1 Orion Platform | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.
|
|||||
| CVE-2019-17125 | 1 Solarwinds | 1 Orion Platform | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.
|
|||||
| CVE-2019-16961 | 1 Solarwinds | 1 Web Help Desk | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
|
|||||
| CVE-2019-16960 | 1 Solarwinds | 1 Web Help Desk | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
|
|||||
| CVE-2019-16959 | 1 Solarwinds | 1 Webhelpdesk | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
|
|||||
| CVE-2019-16958 | 1 Solarwinds | 1 Help Desk | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
|
|||||
| CVE-2019-16957 | 1 Solarwinds | 1 Webhelpdesk | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
|
|||||
| CVE-2019-16956 | 1 Solarwinds | 1 Web Help Desk | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
|
|||||
| CVE-2019-16955 | 1 Solarwinds | 1 Webhelpdesk | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
|
|||||
| CVE-2019-16954 | 1 Solarwinds | 1 Web Help Desk | 2024-11-21 | 4.9 MEDIUM | 5.4 MEDIUM |
|
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
|
|||||
| CVE-2019-13182 | 1 Solarwinds | 1 Serv-u Ftp Server | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
|
|||||
| CVE-2019-13181 | 1 Solarwinds | 1 Serv-u Ftp Server | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
|
|||||
| CVE-2019-12954 | 1 Solarwinds | 2 Network Performance Monitor Orion Platform 2018 Netpath, Network Performance Monitor Orion Platform 2018 Npm | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.
|
|||||
| CVE-2019-12864 | 1 Solarwinds | 3 Netpath, Network Performance Monitor, Orion Platform | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.
|
|||||
| CVE-2019-12863 | 1 Solarwinds | 3 Netpath, Network Performance Monitor, Orion Platform | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.
|
|||||
| CVE-2019-12769 | 1 Solarwinds | 1 Serv-u Managed File Transfer | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
|
|||||
| CVE-2019-12181 | 1 Solarwinds | 2 Serv-u Ftp Server, Serv-u Mft Server | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
|
|||||
| CVE-2018-19999 | 1 Solarwinds | 1 Serv-u Ftp Server | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
|
|||||
| CVE-2018-19934 | 1 Solarwinds | 1 Serv-u Ftp Server | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
|
|||||
| CVE-2018-19386 | 1 Solarwinds | 1 Database Performance Analyzer | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
|
|||||
| CVE-2018-16792 | 1 Solarwinds | 1 Sftp\/scp Server | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
|
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
|
|||||
| CVE-2018-16791 | 1 Solarwinds | 1 Sftp\/scp Server | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
|
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.
|
|||||
| CVE-2018-16243 | 1 Solarwinds | 1 Database Performance Analyzer | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
|
|||||
| CVE-2018-15906 | 1 Solarwinds | 1 Serv-u Ftp Server | 2024-11-21 | 9.0 HIGH | 7.2 HIGH |
|
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
|
|||||
| CVE-2018-13442 | 1 Solarwinds | 1 Network Performance Monitor | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
|
|||||
| CVE-2018-12897 | 1 Solarwinds | 1 Dameware Mini Remote Control | 2024-11-21 | 4.6 MEDIUM | 7.8 HIGH |
|
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
|
|||||
| CVE-2018-10241 | 1 Solarwinds | 1 Serv-u | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.
|
|||||
| CVE-2018-10240 | 1 Solarwinds | 1 Serv-u | 2024-11-21 | 5.0 MEDIUM | 7.3 HIGH |
|
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.
|
|||||
| CVE-2024-45715 | 1 Solarwinds | 1 Solarwinds Platform | 2024-10-30 | N/A | 6.1 MEDIUM |
|
The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.
|
|||||
| CVE-2024-45714 | 1 Solarwinds | 1 Serv-u | 2024-10-30 | N/A | 4.1 MEDIUM |
|
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.
|
|||||
| CVE-2024-45710 | 1 Solarwinds | 1 Solarwinds Platform | 2024-10-17 | N/A | 7.8 HIGH |
|
SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.
|
|||||
| CVE-2024-45711 | 1 Solarwinds | 1 Serv-u | 2024-10-17 | N/A | 8.8 HIGH |
|
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are abused. Authentication is required for this vulnerability
|
|||||
| CVE-2024-28991 | 1 Solarwinds | 1 Access Rights Manager | 2024-09-16 | N/A | 8.8 HIGH |
|
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.
|
|||||
| CVE-2024-28990 | 1 Solarwinds | 1 Access Rights Manager | 2024-09-16 | N/A | 9.8 CRITICAL |
|
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console.
We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.
|
|||||