Skip to main content

Vendor/product archive

solarwinds / log_and_event_manager CVEs

Beta · best-effort

5 CVEs tagged to solarwinds / log_and_event_manager0 Critical, 5 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2017-5199

Published Mar 24, 2017

The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5198

Published Mar 24, 2017

SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7840

Published Oct 15, 2015

The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involvin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7839

Published Oct 15, 2015

SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf inv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5504

Published Sep 4, 2014

SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1