← Back

Solarwinds

solarwinds

317 CVEs • 57 products

Products (57)

Click to collapse
Toggle
Serv U
serv-u
Web Help Desk
web_help_desk
N Central
n-central
Tftp Server
tftp_server
Webhelpdesk
webhelpdesk
Patch Manager
patch_manager
Ftp Voyager
ftp_voyager
Netpath
netpath
Kiwi Cattools
kiwi_cattools
Dameware
dameware
Help Desk
help_desk
Pingdom
pingdom
Sql Sentry
sql_sentry
Dynamips
dynamips

CVEs (317)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
1Serv U
Nov 21, 2024
May 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify t...Show more
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation). This UAC issue leads to a data leak to unauthorized users for a domain, with no log of them accessing the data unless they attempt to modify it. This read-only activity is logged to the original domain and does not specify which domain was accessed.Show less
1Solarwinds
1Serv U
Nov 21, 2024
Apr 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.
1Solarwinds
2Database Performance Analyzer
Database Performance Monitor
Nov 21, 2024
Apr 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
1Solarwinds
1Webhelpdesk
Nov 21, 2024
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.
1Solarwinds
1Web Help Desk
Nov 21, 2024
Mar 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.
1Solarwinds
1Serv U
Oct 27, 2025
Jan 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No d...Show more
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.Show less
1Solarwinds
1Webhelpdesk
Nov 21, 2024
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the datab...Show more
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary data into the database.Show less
1Solarwinds
1Web Help Desk
Nov 21, 2024
Dec 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on t...Show more
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.Show less
1Solarwinds
1Orion Platform
Nov 21, 2024
Dec 20, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
1Solarwinds
1Orion Platform
Nov 21, 2024
Dec 20, 2021
N/A· v4
7.2 HIGH· v3
8.5 HIGH· v2
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerabili...Show more
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.Show less
1Solarwinds
1Orion Platform
Nov 21, 2024
Dec 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information...Show more
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.Show less
1Solarwinds
1Serv U
Nov 21, 2024
Dec 6, 2021
N/A· v4
6.8 MEDIUM· v3
6.8 MEDIUM· v2
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
1Solarwinds
1Serv U
Nov 21, 2024
Dec 6, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Serv-U server responds with valid CSRFToken when the request contains only Session.
1Solarwinds
1Kiwi Syslog Server
Nov 21, 2024
Oct 29, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user i...Show more
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have an identical webpage. The attacker essentially hijacks the user activity intended for the original server and sends them to the other server. This is an attack on both the user and the server.Show less
1Solarwinds
1Kiwi Syslog Server
Nov 21, 2024
Oct 27, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HT...Show more
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the application can be accessed over both HTTP, there is a potential for the cookie can be sent in clear text.Show less
1Solarwinds
1Kiwi Syslog Server
Nov 21, 2024
Oct 27, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applica...Show more
The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the execution of an application. If an attacker could successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure that may be valuable in targeting SWI with malicious intent.Show less
1Solarwinds
1Kiwi Syslog Server
Nov 21, 2024
Oct 27, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by...Show more
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the disclosure of sensitive information such as internal authentication headers appended by reverse proxies.Show less
1Solarwinds
1Kiwi Syslog Server
Nov 21, 2024
Oct 25, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected servi...Show more
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path: "Computer\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Kiwi Syslog Server\Parameters\Application".Show less
1Solarwinds
1Kiwi Cattools
Nov 21, 2024
Oct 22, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or...Show more
As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.Show less
1Solarwinds
1Database Performance Analyzer
Nov 21, 2024
Oct 21, 2021
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would ne...Show more
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.Show less