CVE-2012-4939: XSS
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4939?
CVE-2012-4939 is classified as a medium-severity cross-site scripting vulnerability.
How do I fix CVE-2012-4939?
To fix CVE-2012-4939, upgrade the SolarWinds Orion Network Performance Monitor to version 3.0-HotFix1 or later.
What types of systems are affected by CVE-2012-4939?
CVE-2012-4939 affects the IPAM web interface in SolarWinds IP Address Manager and various versions of SolarWinds Orion Network Performance Monitor.
Can CVE-2012-4939 allow remote attackers to execute scripts?
Yes, CVE-2012-4939 allows remote attackers to inject arbitrary web scripts or HTML through the vulnerable field.
Is user data at risk due to CVE-2012-4939?
Yes, user data may be at risk since CVE-2012-4939 can lead to session hijacking or malicious script execution.