CVE-2017-9538: Input Validation
The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other words, the denial of service is caused by an incorrect implementation of a directory-traversal protection mechanism.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9538?
CVE-2017-9538 is classified as a denial of service vulnerability.
How do I fix CVE-2017-9538?
To remediate CVE-2017-9538, upgrade to a version of SolarWinds Network Performance Monitor newer than 12.0.15300.90.
What are the impacts of CVE-2017-9538?
CVE-2017-9538 can lead to a permanent error message displayed throughout the web application, affecting user access.
Who is affected by CVE-2017-9538?
CVE-2017-9538 impacts users of SolarWinds Network Performance Monitor version 12.0.15300.90 and earlier.
What causes CVE-2017-9538?
CVE-2017-9538 is caused by improper input validation in the 'Upload logo from external path' function.