Skip to main content

Vendor archive

solarwinds CVEs

Beta · best-effort

319 CVEs tagged to vendor solarwinds57 Critical, 130 High, 127 Medium, 5 Low, 0 Unrated.

CVE-2018-19999

Published Jun 7, 2019

The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and exec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19934

Published Mar 21, 2019

SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15906

Published Mar 21, 2019

SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8917

Published Feb 18, 2019

SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16792

Published Dec 5, 2018

SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16791

Published Dec 5, 2018

In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to d…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10241

Published May 16, 2018

A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10240

Published May 16, 2018

SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9538

Published Oct 3, 2017

The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent displ…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9537

Published Oct 3, 2017

Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaS…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7722

Published Apr 12, 2017

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and pa…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7647

Published Apr 10, 2017

SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7646

Published Apr 10, 2017

SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5199

Published Mar 24, 2017

The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5198

Published Mar 24, 2017

SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6803

Published Mar 20, 2017

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5709

Published Jun 24, 2016

SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passw…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3643

Published Jun 17, 2016

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."

CVSS 7.8 · High
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2016-3642

Published Jun 17, 2016

The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the A…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 251-275 of 319 CVEsPage 11 of 13