← Back

Orion Web Performance Monitor

orion_web_performance_monitor

Vendor: Solarwinds • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
2Orion Network Performance Monitor
Orion Web Performance Monitor
Nov 21, 2024
Jun 24, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.
1Solarwinds
2Orion Network Performance Monitor
Orion Web Performance Monitor
Nov 21, 2024
Jun 24, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.
1Solarwinds
2Orion Network Performance Monitor
Orion Web Performance Monitor
Nov 21, 2024
Jun 24, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event.
1Solarwinds
8Orion Ip Address Manager
Orion Netflow Traffic AnalyzerOrion Network Configuration Manager+5 more
May 6, 2026
Mar 10, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic...Show more
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager (IPAM) before 4.3, User Device Tracker (UDT) before 3.2, VoIP & Network Quality Manager (VNQM) before 4.2, Server & Application Manager (SAM) before 6.2, Web Performance Monitor (WPM) before 2.2, and possibly other Solarwinds products, allow remote authenticated users to execute arbitrary SQL commands via the (1) dir or (2) sort parameter to the (a) GetAccounts or (b) GetAccountGroups endpoint.Show less