📦

solarwinds_platform

Vendor: solarwinds

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 8 Remote Access
Total CVEs 30 Total Indexed
Avg. EPSS 0.75% Exploit Prob.
Latest CVE CVE-2024-52612 Feb 11

Security Vulnerability Index

Page 2 / 3
7.5 CVSS

The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.

EPSS: 0.07%
7.5 CVSS

A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited.

EPSS: 0.06%
7.0 CVSS

The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format

EPSS: 0.03%
8.0 CVSS

SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited

EPSS: 1.00%
8.0 CVSS

SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.

EPSS: 0.80%
8.0 CVSS

SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.

EPSS: 0.07%
8.0 CVSS

SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges.

EPSS: 2.28%
8.8 CVSS

 Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.

EPSS: 0.10%
4.3 CVSS

Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource

EPSS: 0.09%
3.5 CVSS

The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML.

EPSS: 0.60%