CVE-2021-35228: Reflected cross site scripting affecting SolarWinds: DPA 2021.3.7388
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35228?
CVE-2021-35228 is a vulnerability that occurred due to missing input sanitization for one of the output fields extracted from headers on a specific section of a page, leading to a reflective cross-site scripting attack.
Which software is affected by CVE-2021-35228?
SolarWinds Database Performance Analyzer version 2021.3.7388 is affected by CVE-2021-35228.
What is the severity of CVE-2021-35228?
The severity of CVE-2021-35228 is medium with a CVSS score of 4.7.
How can an attacker exploit CVE-2021-35228?
An attacker can exploit CVE-2021-35228 by performing a Man-in-the-Middle attack to change the header for a remote host, leading to a reflective cross-site scripting attack.
How can CVE-2021-35228 be mitigated?
To mitigate CVE-2021-35228, it is recommended to apply the necessary patches provided by SolarWinds and ensure that input sanitization is implemented for output fields extracted from headers.