Showing 8 vulnerabilities on this page for solarwinds_platform

Signals CISA KEV Ransomware Nuclei
SolarWinds vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SolarWinds Platform Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.

CWE-427Oct 16, 2024
CVSS7.8v3.1EPSS0.278%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SolarWinds Platform Stored XSS Vulnerability

The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

CWE-79Jun 4, 2024
CVSS7.1v3.1EPSS0.32%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SolarWinds Platform Race Condition Vulnerability

The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.

CWE-362Jun 4, 2024
CVSS6.4v3.1EPSS13.9%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SolarWinds Platform SWQL Injection Vulnerability

The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.

CWE-89Jun 4, 2024
CVSS7.5v3.1EPSS0.349%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SolarWinds Platform Reflected XSS Vulnerability

The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

CWE-79May 20, 2024
CVSS7.9v3.1EPSS0.463%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SolarWinds Platform Cross Site Scripting Vulnerability

The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.

CWE-79Apr 18, 2024
CVSS7.5v3.1EPSS0.696%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SolarWinds Platform SWQL Injection Vulnerability

A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited.

CWE-89Apr 18, 2024
CVSS7.5v3.1EPSS0.59%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SolarWinds Platform Arbitrary Open Redirection Vulnerability

The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format

CWE-601Apr 18, 2024
CVSS7.0v3.1EPSS0.341%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX