CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution. |
1Solarwinds 1Security Event Manager Nov 21, 2024 Nov 23, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT
|
1Solarwinds 1Security Event Manager Nov 21, 2024 Nov 23, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS.
|
1Solarwinds 1Security Event Manager Nov 21, 2024 Nov 23, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 This vulnerability discloses build and services versions in the server response header.
|