VendorsSolarwindsorion_platform2020.2.1
Vulnerabilities

Solarwinds Orion Platform 2016.1 Hotfix 1 2020.2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-10148
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
Published 2020-12-29 · Analyzed
9.8KEVEPSS 0.920
CVE-2020-27871
This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within VulnerabilitySettings.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-11902.
Published 2021-02-10 · Modified
9.0EPSS 0.908
CVE-2021-35212
Blind SQL injection Vulnerability
Published 2021-08-31 · Modified
9.0EPSS 0.016
CVE-2020-27870
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authentication is required to exploit this vulnerability. The specific flaw exists within ExportToPDF.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11917.
Published 2021-02-10 · Modified
7.5EPSS 0.045