CVE-2021-35216: SolarWinds Patch Manager EditResourceControls Deserialization of Untrusted Data Remote Code Execution Vulnerability
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Patch Manager. Authentication is required to exploit this vulnerability. The specific flaw exists within the EditResourceControls endpoint. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE.
— ZDI
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35216?
CVE-2021-35216 is a vulnerability in SolarWinds Patch Manager that allows remote attackers to execute arbitrary code.
How severe is CVE-2021-35216?
CVE-2021-35216 has a severity rating of critical.
What products are affected by CVE-2021-35216?
CVE-2021-35216 affects SolarWinds Patch Manager 2020.2.6 and earlier versions.
Is authentication required to exploit CVE-2021-35216?
Yes, authentication is required to exploit CVE-2021-35216.
How do I fix CVE-2021-35216?
To fix CVE-2021-35216, apply the necessary patches and updates provided by SolarWinds.