CVE-2018-16243: XSS
Published Dec 15, 2020
·Updated
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
Affected Software
2 affected components
SolarWinds Database Performance Analyzer=11.1.468
SolarWinds Database Performance Analyzer=12.0.3074
Event History
Dec 15, 2020
CVE Published
via MITRE·10:31 PM
Data Sourced
via MITRE·10:31 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16243?
CVE-2018-16243 is a vulnerability in SolarWinds Database Performance Analyzer (DPA) versions 11.1.468 and 12.0.3074 that allows for persistent XSS attacks.
2
How severe is CVE-2018-16243?
CVE-2018-16243 has a severity rating of 5.4, which is considered medium.
3
Which versions of SolarWinds Database Performance Analyzer are affected by CVE-2018-16243?
SolarWinds Database Performance Analyzer versions 11.1.468 and 12.0.3074 are affected by CVE-2018-16243.
4
What is the CWE ID of CVE-2018-16243?
The CWE ID of CVE-2018-16243 is 79.
5
How can CVE-2018-16243 be fixed?
To fix CVE-2018-16243, users should update to a patched version of SolarWinds Database Performance Analyzer.