Vulnerabilities
Vulnerable Software
Solarwinds:  Security Vulnerabilities
SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.
CVSS Score
7.5
EPSS Score
0.015
Published
2020-07-07
SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.
CVSS Score
6.1
EPSS Score
0.015
Published
2020-07-07
SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.
CVSS Score
7.5
EPSS Score
0.015
Published
2020-07-07
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
CVSS Score
9.8
EPSS Score
0.07
Published
2020-07-05
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
CVSS Score
9.8
EPSS Score
0.016
Published
2020-07-05
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
CVSS Score
9.8
EPSS Score
0.016
Published
2020-07-05
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event.
CVSS Score
8.8
EPSS Score
0.143
Published
2020-06-24
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.
CVSS Score
5.4
EPSS Score
0.011
Published
2020-06-24
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.
CVSS Score
5.4
EPSS Score
0.011
Published
2020-06-24
SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to a certain .exe file.
CVSS Score
7.3
EPSS Score
0.011
Published
2020-06-07


Contact Us

Shodan ® - All rights reserved