CVE-2021-35222: Resource.aspx Reflected Cross-Site Scripting Vulnerability
Published Aug 31, 2021
·Updated
This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page.
Affected Software
2 affected components
SolarWinds Orion Platform<2020.2.6
Microsoft Windows
Remediation
Information
SolarWinds recommends installing 2020.2.6 Hotfix 1 for the Orion Platform as soon as it becomes available. All customers should implement all the recommendations from the Orion Secure Configuration Guide.
Event History
Aug 31, 2021
CVE Published
via MITRE·12:14 PM
Data Sourced
via MITRE·12:14 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-35222?
CVE-2021-35222 is a vulnerability that allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page.
2
What is the severity of CVE-2021-35222?
The severity of CVE-2021-35222 is critical with a severity value of 9.6.
3
How can I mitigate the Resource.aspx Reflected Cross-Site Scripting vulnerability (CVE-2021-35222)?
You can mitigate the Resource.aspx Reflected Cross-Site Scripting vulnerability (CVE-2021-35222) by applying the Orion Platform 2020.2.6 Hotfix 1.
4
Which software is affected by CVE-2021-35222?
The SolarWinds Orion Platform version up to 2020.2.6 is affected by CVE-2021-35222.
5
Is Microsoft Windows affected by CVE-2021-35222?
No, Microsoft Windows is not affected by CVE-2021-35222.