SolarWinds Vulnerabilities and Affected Products
Vulnerabilities associated with webhelpdesk.
Products
Clear product- SolarWinds Platform41 vulnerabilities
- Serv-U37 vulnerabilities
- Access Rights Manager32 vulnerabilities
- Orion Platform24 vulnerabilities
- access_rights_manager23 vulnerabilities
- Web Help Desk19 vulnerabilities
- solarwinds_platform8 vulnerabilities
- Network Configuration Manager7 vulnerabilities
- SolarWinds Observability Self-Hosted7 vulnerabilities
- Kiwi Syslog Server5 vulnerabilities
- Database Performance Analyzer4 vulnerabilities
- webhelpdesk4 vulnerabilities
- Orion3 vulnerabilities
- Patch Manager3 vulnerabilities
- SolarWinds SEM3 vulnerabilities
- Database Performance Analyzer (DPA)2 vulnerabilities
- Kiwi CatTools2 vulnerabilities
- Network Performance Monitor2 vulnerabilities
- Observability Self-Hosted2 vulnerabilities
- ServU2 vulnerabilities
- SolarWinds2 vulnerabilities
- Dameware Mini Remote Control Service1 vulnerability
- dameware_mini_remote_control1 vulnerability
- Database Performance Monitor1 vulnerability
- DPA1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-28987CRITICAL | SolarWinds Web Help Desk Hardcoded Credential VulnerabilityThe SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. | CVSS9.1v3.1 | EPSS93.2% | PoCs5 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-28986CRITICAL | SolarWinds Web Help Desk Java Deserialization Remote Code Execution VulnerabilitySolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available. | CVSS9.8v3.1 | EPSS84.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-35254HIGH | Authenticated Remote Code Execution in WebHelpDesk 12.7.8SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future. CWE-20Mar 25, 2022 | CVSS8.2v3.1 | EPSS0.998% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-35232MEDIUM | Hard credentials discovered in SolarWinds Web Help Desk which allows to execute Arbitrary Hibernate QueriesHard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary data into the database. CWE-798Dec 27, 2021 | CVSS6.8v3.1 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |