VendorsSolarwindsorion_platformall versions
Vulnerabilities

Solarwinds Orion Platform 2016.1 Hotfix 1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2022-47509
SolarWinds Platform Incorrect Input Neutralization Vulnerability
Published 2023-04-21 · Modified
6.1EPSS 0.005
CVE-2021-35219
ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability
Published 2021-08-31 · Modified
6.0EPSS 0.008
CVE-2021-28674
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the access control on Services/NodeManagement.asmx/DeleteObjNow is incorrect. To exploit this, an attacker must be authenticated and must have node management rights associated with at least one valid group on the platform.
Published 2021-07-27 · Modified
5.5EPSS 0.009
CVE-2019-12864
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.
Published 2020-05-04 · Modified
5.5EPSS 0.005
CVE-2022-36966
Insecure Direct Object Reference Vulnerability: Orion Platform 2020.2.6
Published 2022-10-20 · Modified
5.4EPSS 0.004
CVE-2021-3109
The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context of an administrator account.
Published 2021-03-26 · Modified
4.9EPSS 0.008
CVE-2019-12863
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.
Published 2020-02-25 · Modified
4.8EPSS 0.011
CVE-2021-35238
Stored XSS through URL POST parameter in CreateExternalWebsite Vulnerability
Published 2021-09-01 · Modified
4.8EPSS 0.011
CVE-2020-35856
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
Published 2021-03-26 · Modified
4.8EPSS 0.007
← Prev2 / 2