First published: Thu Apr 21 2022(Updated: )
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Database Performance Analyzer | <2022.2 | |
Solarwinds Database Performance Monitor | <=2022.1.7779 |
SolarWinds recommends customers upgrade to the latest version once it becomes generally available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-35229.
The title of the vulnerability is 'Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query'.
The severity of CVE-2021-35229 is medium (6.1).
SolarWinds Database Performance Analyzer and Solarwinds Database Performance Monitor versions up to 2022.1.7779 are affected.
This vulnerability can be exploited by using a complex SQL query that allows cross-site scripting attacks.