CVE-2021-35216
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.
Affected (1)
Products: Solarwinds: Patch Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2020.2.6 |
References (6)
Source: psirt@solarwinds.com
Release NotesVendor Advisory
Source: psirt@solarwinds.com
PatchVendor Advisory
Source: psirt@solarwinds.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.