CVE-2025-26398
- EPSS 0.01%
- Veröffentlicht 12.08.2025 08:10:54
- Zuletzt bearbeitet 17.11.2025 16:10:05
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not inst...
CVE-2023-33231
- EPSS 0.49%
- Veröffentlicht 18.07.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 08:05:12
XSS attack was possible in DPA 2023.2 due to insufficient input validation
CVE-2023-23837
- EPSS 0.66%
- Veröffentlicht 25.04.2023 18:15:09
- Zuletzt bearbeitet 04.02.2025 17:15:11
No exception handling vulnerability which revealed sensitive or excessive information to users.
CVE-2023-23838
- EPSS 0.76%
- Veröffentlicht 25.04.2023 18:15:09
- Zuletzt bearbeitet 04.02.2025 17:15:11
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
CVE-2022-38110
- EPSS 3.4%
- Veröffentlicht 20.01.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:15:48
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
CVE-2022-38112
- EPSS 0.55%
- Veröffentlicht 20.01.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:15:49
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
CVE-2021-35229
- EPSS 0.77%
- Veröffentlicht 21.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:06
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
CVE-2021-35228
- EPSS 1.25%
- Veröffentlicht 21.10.2021 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:12:06
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Mid...
CVE-2018-16243
- EPSS 3.5%
- Veröffentlicht 15.12.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 03:52:21
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and centr...
CVE-2018-19386
- EPSS 23.27%
- Veröffentlicht 14.08.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 03:57:49
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.