VendorsSolarwindsorion_platformall versions
Vulnerabilities

Solarwinds Orion Platform 2016.1 Hotfix 1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2021-25274
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.
Published 2021-02-03 · Modified
10.0EPSS 0.364
CVE-2020-10148
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
Published 2020-12-29 · Analyzed
9.8KEVEPSS 0.920
CVE-2021-27258
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.
Published 2021-04-14 · Modified
9.8EPSS 0.040
CVE-2019-9546
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
Published 2019-03-01 · Modified
9.8EPSS 0.028
CVE-2021-35222
Resource.aspx Reflected Cross-Site Scripting Vulnerability
Published 2021-08-31 · Modified
9.6EPSS 0.026
CVE-2020-27871
This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within VulnerabilitySettings.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-11902.
Published 2021-02-10 · Modified
9.0EPSS 0.908
CVE-2021-35213
Orion User setting Improper Access Control Privilege Escalation Vulnerability
Published 2021-08-31 · Modified
9.0EPSS 0.034
CVE-2020-13169
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
Published 2020-09-17 · Modified
9.0EPSS 0.022
CVE-2021-35212
Blind SQL injection Vulnerability
Published 2021-08-31 · Modified
9.0EPSS 0.016
CVE-2021-35218
Chart Endpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published 2021-09-01 · Modified
8.9EPSS 0.764
CVE-2021-35215
ActionPluginBaseView Deserialization of Untrusted Data RCE
Published 2021-09-01 · Modified
8.9EPSS 0.697
CVE-2022-36958
SolarWinds Platform Deserialization of Untrusted Data
Published 2022-10-20 · Modified
8.8EPSS 0.815
CVE-2022-36961
Orion Platform SQL Injection Privilege Escalation Vulnerability
Published 2022-09-30 · Modified
8.8EPSS 0.742
CVE-2022-36964
SolarWinds Platform Deserialization of Untrusted Data
Published 2022-11-29 · Modified
8.8EPSS 0.168
CVE-2021-35234
Exposed Dangerous Functions - Privileged Escalation
Published 2021-12-20 · Modified
8.8EPSS 0.028
CVE-2022-36960
SolarWinds Platform Improper Input Validation
Published 2022-11-29 · Modified
8.8EPSS 0.009
CVE-2021-35244
Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6
Published 2021-12-20 · Modified
8.5EPSS 0.058
CVE-2021-35220
EmailWebPage Command Injection RCE
Published 2021-08-31 · Modified
8.1EPSS 0.025
CVE-2021-35221
ImportAlert Improper Access Control Tampering Vulnerability
Published 2021-08-31 · Modified
8.1EPSS 0.020
CVE-2021-27277
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the OneTimeJobSchedulerEventsService WCF service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-11955.
Published 2021-04-22 · Modified
7.8EPSS 0.011
CVE-2022-47506
SolarWinds Platform Directory Traversal Vulnerability
Published 2023-02-15 · Modified
7.8EPSS 0.006
CVE-2021-25275
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected by SolarWinds applications, and leads to admin access to the applications by inserting or changing authentication data stored in the Accounts table of the database.
Published 2021-02-03 · Modified
7.8EPSS 0.006
CVE-2022-47505
SolarWinds Platform Local Privilege Escalation Vulnerability
Published 2023-04-21 · Modified
7.8EPSS 0.002
CVE-2020-27870
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authentication is required to exploit this vulnerability. The specific flaw exists within ExportToPDF.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11917.
Published 2021-02-10 · Modified
7.5EPSS 0.045
CVE-2021-35239
Stored XSS in Maps text box hyperlink Vulnerability
Published 2021-08-31 · Modified
7.5EPSS 0.010
CVE-2022-38111
SolarWinds Platform Deserialization of Untrusted Data Vulnerability
Published 2023-02-15 · Modified
7.2EPSS 0.848
CVE-2023-23836
SolarWinds Platform Deserialization of Untrusted Data Vulnerability
Published 2023-02-15 · Modified
7.2EPSS 0.803
CVE-2022-38108
SolarWinds Platform Deserialization of Untrusted Data
Published 2022-10-20 · Modified
7.2EPSS 0.689
CVE-2022-47504
SolarWinds Platform Deserialization of Untrusted Data Vulnerability
Published 2023-02-15 · Modified
7.2EPSS 0.251
CVE-2022-47503
SolarWinds Platform Deserialization of Untrusted Data Vulnerability
Published 2023-02-15 · Modified
7.2EPSS 0.244
CVE-2022-36957
SolarWinds Platform Deserialization of Untrusted Data
Published 2022-10-20 · Modified
7.2EPSS 0.128
CVE-2022-36962
SolarWinds Platform Command Injection
Published 2022-11-29 · Modified
7.2EPSS 0.093
CVE-2022-36963
SolarWinds Platform Deserialization of Untrusted Data Vulnerability
Published 2023-04-21 · Modified
7.2EPSS 0.082
CVE-2022-47507
SolarWinds Platform Deserialization of Untrusted Data Vulnerability
Published 2023-02-15 · Modified
7.2EPSS 0.072
CVE-2023-23840
SolarWinds Platform Exposed Dangerous Method Vulnerability
Published 2023-09-13 · Modified
7.2EPSS 0.054
CVE-2023-23845
SolarWinds Platform Exposed Dangerous Method Vulnerability
Published 2023-09-13 · Modified
7.2EPSS 0.054
CVE-2021-35248
Unrestricted access to Orion.UserSettings SWIS entity for low-privilege users
Published 2021-12-20 · Modified
6.8EPSS 0.009
CVE-2021-35240
Stored XSS via Help Server settings
Published 2021-08-31 · Modified
6.5EPSS 0.011
CVE-2019-17127
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.
Published 2020-01-17 · Modified
6.1EPSS 0.019
CVE-2019-17125
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.
Published 2020-01-17 · Modified
6.1EPSS 0.015
1 / 2Next →