CVE-2023-33225
- EPSS 0.11%
- Veröffentlicht 26.07.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:05:10
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
CVE-2023-33224
- EPSS 0.13%
- Veröffentlicht 26.07.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 08:05:10
The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
CVE-2023-23844
- EPSS 0.11%
- Veröffentlicht 26.07.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:46:56
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
CVE-2023-23843
- EPSS 0.11%
- Veröffentlicht 26.07.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:46:56
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
CVE-2023-23839
- EPSS 0.48%
- Veröffentlicht 25.04.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:46:55
The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information.
CVE-2022-47512
- EPSS 0.09%
- Veröffentlicht 19.12.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:32:06
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected
CVE-2022-36965
- EPSS 1.02%
- Veröffentlicht 30.09.2022 17:15:13
- Zuletzt bearbeitet 20.05.2025 17:15:45
Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).