First published: Wed Oct 31 2012(Updated: )
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Orion IP Address Manager | <=3.0 | |
SolarWinds Orion | ||
SolarWinds Orion | =10.0 | |
SolarWinds Orion | =10.1 | |
SolarWinds Orion | =10.1.13.0 | |
SolarWinds Orion | =10.2 | |
SolarWinds Orion | =10.2.1 | |
SolarWinds Orion | =10.2.2 | |
SolarWinds Orion | =10.3 | |
SolarWinds Orion | =10.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4939 is classified as a medium-severity cross-site scripting vulnerability.
To fix CVE-2012-4939, upgrade the SolarWinds Orion Network Performance Monitor to version 3.0-HotFix1 or later.
CVE-2012-4939 affects the IPAM web interface in SolarWinds IP Address Manager and various versions of SolarWinds Orion Network Performance Monitor.
Yes, CVE-2012-4939 allows remote attackers to inject arbitrary web scripts or HTML through the vulnerable field.
Yes, user data may be at risk since CVE-2012-4939 can lead to session hijacking or malicious script execution.