Vulnerabilities > Solarwinds

DATE CVE VULNERABILITY TITLE RISK
2021-12-20 CVE-2021-35234 SQL Injection vulnerability in Solarwinds Orion Platform
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation.
network
low complexity
solarwinds CWE-89
8.8
2021-12-20 CVE-2021-35244 Unrestricted Upload of File with Dangerous Type vulnerability in Solarwinds Orion Platform
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file.
network
low complexity
solarwinds CWE-434
7.2
2021-12-20 CVE-2021-35248 Incorrect Permission Assignment for Critical Resource vulnerability in Solarwinds Orion Platform
It has been reported that any Orion user, e.g.
network
low complexity
solarwinds CWE-732
4.3
2021-12-06 CVE-2021-35242 Cross-Site Request Forgery (CSRF) vulnerability in Solarwinds Serv-U
Serv-U server responds with valid CSRFToken when the request contains only Session.
network
low complexity
solarwinds CWE-352
8.8
2021-12-06 CVE-2021-35245 Unspecified vulnerability in Solarwinds Serv-U
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
network
low complexity
solarwinds
6.8
2021-10-29 CVE-2021-35237 Improper Restriction of Rendered UI Layers or Frames vulnerability in Solarwinds Kiwi Syslog Server
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking.
network
low complexity
solarwinds CWE-1021
4.3
2021-10-27 CVE-2021-35233 Unspecified vulnerability in Solarwinds Kiwi Syslog Server
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier.
network
low complexity
solarwinds
5.3
2021-10-27 CVE-2021-35235 Unspecified vulnerability in Solarwinds Kiwi Syslog Server
The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions.
network
low complexity
solarwinds
5.3
2021-10-27 CVE-2021-35236 Missing Encryption of Sensitive Data vulnerability in Solarwinds Kiwi Syslog Server
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions.
network
low complexity
solarwinds CWE-311
5.3
2021-10-25 CVE-2021-35231 Unquoted Search Path or Element vulnerability in Solarwinds Kiwi Syslog Server
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.
local
low complexity
solarwinds CWE-428
6.7