Vulnerabilities (CVE)

Vendor filter

Solarwinds Subscribe

Filter

46 total CVE
CVE Vendors Products Updated CVSS
CVE-2019-3980 1 Solarwinds 1 Dameware Mini Remote Control Firmware 2019-10-15 10.0
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login...
CVE-2018-15906 1 Solarwinds 1 Serv-u Ftp Server 2019-10-03 9.0
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
CVE-2017-5198 1 Solarwinds 1 Log And Event Manager 2019-10-03 7.2
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.
CVE-2018-16791 1 Solarwinds 1 Sftp%2fscp Server 2019-10-03 5.0
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also...
CVE-2017-7647 1 Solarwinds 1 Log %26 Event Manager 2019-10-03 6.5
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.
CVE-2017-5199 1 Solarwinds 1 Log And Event Manager 2019-10-03 6.5
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.
CVE-2018-19386 1 Solarwinds 1 Database Performance Analyzer 2019-08-27 4.3
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
CVE-2018-13442 1 Solarwinds 1 Network Performance Monitor 2019-07-18 6.5
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
CVE-2018-19999 1 Solarwinds 1 Serv-u Ftp Server 2019-06-10 7.2
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to...
CVE-2019-9546 1 Solarwinds 1 Orion Platform 2019-05-07 7.5
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
CVE-2019-9017 1 Solarwinds 1 Damewire Mini Remote Control 2019-05-04 5.0
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
CVE-2018-19934 1 Solarwinds 1 Serv-u Ftp Server 2019-03-25 3.5
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
CVE-2019-8917 1 Solarwinds 1 Orion Network Performance Monitor 2019-02-19 10.0
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call...
CVE-2018-16792 1 Solarwinds 1 Sftp%2fscp Server 2018-12-31 6.4
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
CVE-2006-1951 1 Solarwinds 1 Tftp Server 2018-10-18 5.0
Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.
CVE-2010-4828 1 Solarwinds 1 Orion Network Performance Monitor 2018-10-10 4.3
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to MapView.aspx; NetObject parameter to (2)...
CVE-2017-9538 1 Solarwinds 1 Network Performance Monitor 2018-10-09 4.0
The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message...
CVE-2017-9537 1 Solarwinds 1 Network Performance Monitor 2018-10-09 3.5
Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaScript into various vulnerable parameters.
CVE-2018-10240 1 Solarwinds 1 Serv-u 2018-06-25 5.0
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by...
CVE-2018-10241 1 Solarwinds 1 Serv-u 2018-06-20 4.0
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.