Vulnerabilities > Solarwinds > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-07-05 CVE-2020-15541 Unspecified vulnerability in Solarwinds Serv-U FTP Server
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
network
low complexity
solarwinds
critical
9.8
2019-10-08 CVE-2019-3980 Origin Validation Error vulnerability in Solarwinds Dameware Mini Remote Control 12.1.0.89
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host.
network
low complexity
solarwinds CWE-346
critical
9.8
2019-03-01 CVE-2019-9546 Uncontrolled Search Path Element vulnerability in Solarwinds Orion Platform
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
network
low complexity
solarwinds CWE-427
critical
9.8
2019-02-18 CVE-2019-8917 Unspecified vulnerability in Solarwinds Orion Network Performance Monitor
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service.
network
low complexity
solarwinds
critical
9.8
2018-12-05 CVE-2018-16792 XXE vulnerability in Solarwinds Sftp/Scp Server 20180910
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
network
low complexity
solarwinds CWE-611
critical
9.1
2018-12-05 CVE-2018-16791 Insufficiently Protected Credentials vulnerability in Solarwinds Sftp/Scp Server 20180910
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts.
network
low complexity
solarwinds CWE-522
critical
9.8
2017-12-20 CVE-2012-2576 SQL Injection vulnerability in Solarwinds Backup Profiler, Storage Manager and Storage Profiler
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
network
low complexity
solarwinds CWE-89
critical
9.8
2017-04-12 CVE-2017-7722 Command Injection vulnerability in Solarwinds LOG & Event Manager 6.3.1
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password).
network
low complexity
solarwinds CWE-77
critical
10.0
2016-06-17 CVE-2016-3642 Unspecified vulnerability in Solarwinds Virtualization Manager 6.3.1
The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
network
low complexity
solarwinds
critical
9.8
2016-05-09 CVE-2016-4350 SQL Injection vulnerability in Solarwinds Storage Resource Monitor 6.2.1
Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) ScriptSchedule parameter in the ScriptServlet servlet; the (2) winEventId or (3) winEventLog parameter in the WindowsEventLogsServlet servlet; the (4) processOS parameter in the ProcessesServlet servlet; the (5) group, (6) groupName, or (7) clientName parameter in the BackupExceptionsServlet servlet; the (8) valDB or (9) valFS parameter in the BackupAssociationServlet servlet; the (10) orderBy or (11) orderDir parameter in the HostStorageServlet servlet; the (12) fileName, (13) sortField, or (14) sortDirection parameter in the DuplicateFilesServlet servlet; the (15) orderFld or (16) orderDir parameter in the QuantumMonitorServlet servlet; the (17) exitCode parameter in the NbuErrorMessageServlet servlet; the (18) udfName, (19) displayName, (20) udfDescription, (21) udfDataValue, (22) udfSectionName, or (23) udfId parameter in the UserDefinedFieldConfigServlet servlet; the (24) sortField or (25) sortDirection parameter in the XiotechMonitorServlet servlet; the (26) sortField or (27) sortDirection parameter in the BexDriveUsageSummaryServlet servlet; the (28) state parameter in the ScriptServlet servlet; the (29) assignedNames parameter in the FileActionAssignmentServlet servlet; the (30) winEventSource parameter in the WindowsEventLogsServlet servlet; or the (31) name, (32) ipOne, (33) ipTwo, or (34) ipThree parameter in the XiotechMonitorServlet servlet.
network
low complexity
solarwinds CWE-89
critical
9.8