Vulnerabilities > Solarwinds > High

DATE CVE VULNERABILITY TITLE RISK
2019-07-16 CVE-2018-13442 SQL Injection vulnerability in Solarwinds Network Performance Monitor
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
network
low complexity
solarwinds CWE-89
8.8
2019-06-17 CVE-2019-12181 OS Command Injection vulnerability in Solarwinds Serv-U FTP Server and Serv-U MFT Server
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
network
low complexity
solarwinds CWE-78
8.8
2019-06-07 CVE-2019-3957 Out-of-bounds Read vulnerability in Solarwinds Dameware Mini Remote Control
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.
network
high complexity
solarwinds CWE-125
7.4
2019-06-07 CVE-2018-19999 Improper Authentication vulnerability in Solarwinds Serv-U FTP Server 15.1.6.25
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation.
local
low complexity
solarwinds CWE-287
7.8
2019-05-02 CVE-2019-9017 Out-of-bounds Write vulnerability in Solarwinds Dameware Mini Remote Control 10.0
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
network
low complexity
solarwinds CWE-787
7.5
2019-03-21 CVE-2018-15906 Unspecified vulnerability in Solarwinds Serv-U FTP Server 15.1.6
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
network
low complexity
solarwinds
7.2
2018-09-07 CVE-2018-12897 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Solarwinds Dameware Mini Remote Control
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
local
low complexity
solarwinds CWE-119
7.8
2018-05-16 CVE-2018-10240 Insufficient Entropy vulnerability in Solarwinds Serv-U
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie.
network
low complexity
solarwinds CWE-331
7.3
2017-04-10 CVE-2017-7647 Unspecified vulnerability in Solarwinds LOG & Event Manager 6.3.1
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.
network
low complexity
solarwinds
8.8
2017-03-24 CVE-2017-5199 Incorrect Permission Assignment for Critical Resource vulnerability in Solarwinds LOG and Event Manager
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.
network
low complexity
solarwinds CWE-732
8.8