6

CVE-2021-35219

ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability

ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Settings page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SolarwindsOrion Platform Version < 2020.2.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.532
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
psirt@solarwinds.com 6 1.5 4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm
Vendor Advisory
Product
Release Notes
https://support.solarwinds.com/SuccessCenter/s/article/Mitigate-the-ExportToPdfCmd-Arbitrary-File-Read-Information-Disclosure-CVE-2021-35219?language=en_US
Patch
Vendor Advisory
Mitigation
https://support.solarwinds.com/SuccessCenter/s/article/Orion-Platform-2020-2-6-Hotfix-1?language=en_US
Patch
Vendor Advisory
Release Notes
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35219
Vendor Advisory