CVE-2021-35227: Insecure Web Configuration for RabbitMQ Management Plugin in SolarWinds ARM
The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35227?
CVE-2021-35227 is a vulnerability in the RabbitMQ Plugin in SolarWinds Access Rights Manager (ARM) 2020.2.6 that allows the HTTP interface to be enabled without the ability to configure HTTPS.
How severe is CVE-2021-35227?
CVE-2021-35227 has a severity score of 7.8 (high).
How does CVE-2021-35227 affect SolarWinds Access Rights Manager?
CVE-2021-35227 affects SolarWinds Access Rights Manager (ARM) 2020.2.6 by enabling the HTTP interface without the ability to configure HTTPS.
How can I fix CVE-2021-35227?
To fix CVE-2021-35227, upgrade to a version of SolarWinds Access Rights Manager (ARM) that includes the ability to configure HTTPS for the RabbitMQ Plugin.
Where can I find more information about CVE-2021-35227?
You can find more information about CVE-2021-35227 in the SolarWinds documentation and the SolarWinds Trust Center security advisories.