← Back

Orion Platform

orion_platform

Vendor: Solarwinds • 49 CVEs

CVEs (49)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
1Orion Platform
Jun 17, 2026
Feb 3, 2021
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users....Show more
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected by SolarWinds applications, and leads to admin access to the applications by inserting or changing authentication data stored in the Accounts table of the database.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Feb 3, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to T...Show more
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Dec 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API com...Show more
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Sep 17, 2020
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeov...Show more
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).Show less
1Solarwinds
3Netpath
Network Performance MonitorOrion Platform
Jun 17, 2026
May 4, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Interna...Show more
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.Show less
1Solarwinds
3Netpath
Network Performance MonitorOrion Platform
Jun 17, 2026
Feb 25, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.
1Solarwinds
1Orion Platform
Jun 17, 2026
Jan 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbo...Show more
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Jan 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achi...Show more
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Mar 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.