First published: Wed Dec 20 2017(Updated: )
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Backup Profiler | <5.1.2 | |
SolarWinds Storage Manager | <5.1.2 | |
SolarWinds Storage Profiler | <5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2576 has a high severity rating due to its potential for remote SQL injection attacks.
To fix CVE-2012-2576, upgrade to version 5.1.2 or later of the affected SolarWinds products.
CVE-2012-2576 affects SolarWinds Backup Profiler, Storage Manager, and Storage Profiler prior to version 5.1.2.
CVE-2012-2576 is classified as an SQL injection vulnerability.
Yes, CVE-2012-2576 can allow attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access.