First published: Thu Oct 19 2023(Updated: )
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated user to achieve the Remote Code Execution.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Access Rights Manager | <=2023.2.0.73 |
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-35187 is critical with a CVSS score of 9.8.
CVE-2023-35187 affects SolarWinds Access Rights Manager version 2023.2.0.73 and allows an unauthenticated user to achieve remote code execution.
Yes, CVE-2023-35187 is a directory traversal remote code vulnerability.
To fix CVE-2023-35187, it is recommended to update to the latest version of SolarWinds Access Rights Manager.
You can find more information about CVE-2023-35187 in the release notes of SolarWinds Access Rights Manager version 2023.2.1 and the SolarWinds Trust Center security advisories page.