CVE-2021-35244
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
Affected (4)
Products: Solarwinds: Orion Platform
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2020.2.6 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (8)
Source: psirt@solarwinds.com
Vendor Advisory
Source: psirt@solarwinds.com
Release NotesVendor Advisory
Source: psirt@solarwinds.com
Not ApplicableVendor Advisory
Source: psirt@solarwinds.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.