First published: Thu Oct 19 2023(Updated: )
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Access Rights Manager | <=2023.2.0.73 |
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35182 is a vulnerability in the SolarWinds Access Rights Manager that allows unauthenticated users to execute remote code.
CVE-2023-35182 has a severity rating of 9.8 (critical).
The SolarWinds Access Rights Manager version 2023.2.0.73 is affected by CVE-2023-35182.
An unauthenticated user can exploit CVE-2023-35182 by executing remote code on the SolarWinds ARM Server.
You can find more information about CVE-2023-35182 in the SolarWinds documentation and security advisories.