CVE-2023-33231: XSS in SolarWinds Database Performance Analyzer 2023.2
XSS attack was possible in DPA 2023.2 due to insufficient input validation
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Database Performance Analyzerto a version that resolves this vulnerability.Fixed in 2023.2.100
Event History
Frequently Asked Questions
What is CVE-2023-33231?
CVE-2023-33231 is a vulnerability in Solarwinds Database Performance Analyzer (DPA) 2023.2 that allows for XSS attacks due to insufficient input validation.
How severe is CVE-2023-33231?
CVE-2023-33231 has a severity rating of medium with a score of 6.1.
How does CVE-2023-33231 affect Solarwinds Database Performance Analyzer?
CVE-2023-33231 affects Solarwinds Database Performance Analyzer (DPA) 2023.2, allowing for XSS attacks due to insufficient input validation.
How can I fix CVE-2023-33231?
To fix CVE-2023-33231, upgrade Solarwinds Database Performance Analyzer (DPA) to version 2023.2.100 or later.
Where can I find more information about CVE-2023-33231?
More information about CVE-2023-33231 can be found at the following references: [Solarwinds Security Advisories](https://www.solarwinds.com/trust-center/security-advisories/CVE-2023-33231) and [Solarwinds DPA 2023.2.100 Release Notes](https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-2-100_release_notes.htm).