Showing 4 vulnerabilities on this page for webhelpdesk

Signals CISA KEV Ransomware Nuclei
SolarWinds vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SolarWinds Web Help Desk Hardcoded Credential Vulnerability

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

CWE-798Aug 21, 20241 related artifact
CVSS9.1v3.1EPSS93.2%PoCs5SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.   However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.

CWE-502Aug 13, 20241 related artifact
CVSS9.8v3.1EPSS84.6%PoCs0SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Authenticated Remote Code Execution in WebHelpDesk 12.7.8

SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.

CWE-20Mar 25, 2022
CVSS8.2v3.1EPSS0.998%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Hard credentials discovered in SolarWinds Web Help Desk which allows to execute Arbitrary Hibernate Queries

Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary data into the database.

CWE-798Dec 27, 2021
CVSS6.8v3.1EPSS0.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX