Filtered by vendor Solarwinds Subscriptions
Total 253 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-35252 1 Solarwinds 1 Serv-u 2023-10-23 7.5 High
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
CVE-2021-35246 1 Solarwinds 1 Engineer\'s Toolset 2023-10-23 5.3 Medium
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
CVE-2019-9017 1 Solarwinds 1 Dameware Mini Remote Control 2023-09-25 7.5 High
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
CVE-2023-40060 1 Solarwinds 1 Serv-u 2023-09-14 7.2 High
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4.  SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1. 
CVE-2023-35179 1 Solarwinds 1 Serv-u 2023-09-14 7.2 High
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 
CVE-2022-38112 1 Solarwinds 1 Database Performance Analyzer 2023-09-14 7.5 High
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
CVE-2021-35211 1 Solarwinds 1 Serv-u 2023-08-08 10.0 Critical
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.
CVE-2023-33231 1 Solarwinds 1 Database Performance Analyzer 2023-08-03 6.1 Medium
XSS attack was possible in DPA 2023.2 due to insufficient input validation
CVE-2023-33224 1 Solarwinds 1 Solarwinds Platform 2023-08-03 7.2 High
The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
CVE-2023-23844 1 Solarwinds 1 Solarwinds Platform 2023-08-03 7.2 High
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
CVE-2023-23843 1 Solarwinds 1 Solarwinds Platform 2023-08-03 7.2 High
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
CVE-2023-23839 1 Solarwinds 1 Solarwinds Platform 2023-08-03 6.5 Medium
The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information.
CVE-2023-23838 2 Microsoft, Solarwinds 2 Windows, Database Performance Analyzer 2023-08-03 6.5 Medium
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
CVE-2023-23837 2 Microsoft, Solarwinds 2 Windows, Database Performance Analyzer 2023-08-03 7.5 High
No exception handling vulnerability which revealed sensitive or excessive information to users.
CVE-2023-23836 1 Solarwinds 1 Orion Platform 2023-08-03 7.2 High
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands.
CVE-2022-47512 2 Microsoft, Solarwinds 2 Windows, Solarwinds Platform 2023-08-03 5.5 Medium
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected
CVE-2022-47509 1 Solarwinds 1 Orion Platform 2023-08-03 6.1 Medium
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.
CVE-2022-47507 1 Solarwinds 1 Orion Platform 2023-08-03 7.2 High
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
CVE-2022-47506 1 Solarwinds 1 Orion Platform 2023-08-03 7.8 High
SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default configuration, enabling the execution of arbitrary commands.
CVE-2022-47505 1 Solarwinds 1 Orion Platform 2023-08-03 7.8 High
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.