First published: Tue Jul 16 2019(Updated: )
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Network Performance Monitor | <=12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-13442 is high.
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
To fix CVE-2018-13442, it is recommended to update SolarWinds Network Performance Monitor to a version that is not affected by this vulnerability.
The Common Weakness Enumeration (CWE) ID for CVE-2018-13442 is CWE-89.
You can find more information about CVE-2018-13442 at https://labs.nettitude.com/blog/cve-2018-13442-solarwinds-npm-sql-injection/