First published: Thu Oct 19 2023(Updated: )
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileges.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=2023.2.0.73 |
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35185 refers to a Directory Traversal Remote Code Vulnerability in the SolarWinds Access Rights Manager, allowing an attacker to execute code remotely with SYSTEM privileges.
The severity of CVE-2023-35185 is classified as high, with a severity value of 8.8.
The affected version of SolarWinds Access Rights Manager is up to and inclusive of version 2023.2.0.73.
To fix CVE-2023-35185, it is recommended to update SolarWinds Access Rights Manager to a version that is not affected by the vulnerability.
You can find more information about CVE-2023-35185 in the release notes of the SolarWinds Access Rights Manager and the SolarWinds Trust Center security advisories.