Vulnerabilities > Solarwinds > Database Performance Analyzer > Low

DATE CVE VULNERABILITY TITLE RISK
2021-10-21 CVE-2021-35228 Cross-site Scripting vulnerability in Solarwinds Database Performance Analyzer 2021.3.7388
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack.
network
high complexity
solarwinds CWE-79
2.6
2020-12-15 CVE-2018-16243 Cross-site Scripting vulnerability in Solarwinds Database Performance Analyzer 11.1.468/12.0.3074
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
network
solarwinds CWE-79
3.5