First published: Thu Oct 21 2021(Updated: )
The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Access Rights Manager | <=2020.2.6 |
SolarWinds recommends installing 2021.4 for the ARM as soon as it becomes available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35227 is a vulnerability in the RabbitMQ Plugin in SolarWinds Access Rights Manager (ARM) 2020.2.6 that allows the HTTP interface to be enabled without the ability to configure HTTPS.
CVE-2021-35227 has a severity score of 7.8 (high).
CVE-2021-35227 affects SolarWinds Access Rights Manager (ARM) 2020.2.6 by enabling the HTTP interface without the ability to configure HTTPS.
To fix CVE-2021-35227, upgrade to a version of SolarWinds Access Rights Manager (ARM) that includes the ability to configure HTTPS for the RabbitMQ Plugin.
You can find more information about CVE-2021-35227 in the SolarWinds documentation and the SolarWinds Trust Center security advisories.