CVE-2018-13442: SQL Injection
Published Jul 16, 2019
·Updated
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
Affected Software
1 affected component
SolarWinds Network Performance Monitor<=12.3
Remediation
Event History
Jul 16, 2019
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13442?
The severity of CVE-2018-13442 is high.
2
How does SolarWinds Network Performance Monitor 12.3 allow SQL injection?
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
3
How can I fix CVE-2018-13442?
To fix CVE-2018-13442, it is recommended to update SolarWinds Network Performance Monitor to a version that is not affected by this vulnerability.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-13442?
The Common Weakness Enumeration (CWE) ID for CVE-2018-13442 is CWE-89.
5
Where can I find more information about CVE-2018-13442?
You can find more information about CVE-2018-13442 at https://labs.nettitude.com/blog/cve-2018-13442-solarwinds-npm-sql-injection/