📦

solarwinds_platform

Vendor: solarwinds

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 8 Remote Access
Total CVEs 30 Total Indexed
Avg. EPSS 0.75% Exploit Prob.
Latest CVE CVE-2024-52612 Feb 11

Security Vulnerability Index

Page 3 / 3
7.2 CVSS

The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.

EPSS: 0.21%
7.2 CVSS

The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

EPSS: 0.25%
7.2 CVSS

The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.

EPSS: 0.22%
7.2 CVSS

The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.

EPSS: 0.21%
6.5 CVSS

The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information.

EPSS: 2.35%
5.5 CVSS

Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected

EPSS: 0.21%
6.1 CVSS

Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).

EPSS: 2.60%