CVE-2021-35229: Cross-Site Scripting Vulnerability using SQL Query
Published Apr 21, 2022
·Updated
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
Affected Software
2 affected components
SolarWinds Database Performance Analyzer<2022.2
SolarWinds Database Performance Monitor<=2022.1.7779
Remediation
Information
SolarWinds recommends customers upgrade to the latest version once it becomes generally available.
Event History
Apr 21, 2022
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-35229.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query'.
3
What is the severity of CVE-2021-35229?
The severity of CVE-2021-35229 is medium (6.1).
4
What software is affected by CVE-2021-35229?
SolarWinds Database Performance Analyzer and Solarwinds Database Performance Monitor versions up to 2022.1.7779 are affected.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by using a complex SQL query that allows cross-site scripting attacks.