Vulnerabilities > Solarwinds > Orion Platform > 2018.4

DATE CVE VULNERABILITY TITLE RISK
2021-02-03 CVE-2021-25274 Deserialization of Untrusted Data vulnerability in Solarwinds Orion Platform
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues.
network
low complexity
solarwinds CWE-502
critical
9.8
2020-09-17 CVE-2020-13169 Cross-site Scripting vulnerability in Solarwinds Orion Platform
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages.
network
low complexity
solarwinds CWE-79
critical
9.0
2020-05-04 CVE-2019-12864 Information Exposure Through an Error Message vulnerability in Solarwinds products
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.
local
low complexity
solarwinds CWE-209
5.5
2020-02-25 CVE-2019-12863 Cross-site Scripting vulnerability in Solarwinds products
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.
network
low complexity
solarwinds CWE-79
4.8
2019-03-01 CVE-2019-9546 Uncontrolled Search Path Element vulnerability in Solarwinds Orion Platform
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
network
low complexity
solarwinds CWE-427
critical
9.8