CVE-2023-35188: SQL Injection Remote Code Execution Vulnerability
Published Feb 6, 2024
·Updated
SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.
Affected Software
1 affected component
SolarWinds SolarWinds Platform<2024.1
Remediation
Information
SolarWinds recommends that customers upgrade to the SolarWinds Platform 2024.1
Event History
Feb 6, 2024
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 25, 56091
Event
via NVD·11:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-35188?
CVE-2023-35188 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2023-35188?
To fix CVE-2023-35188, users should upgrade to version 2024.1 or later of the SolarWinds Platform.
3
What systems are affected by CVE-2023-35188?
CVE-2023-35188 affects all versions of the SolarWinds Platform prior to version 2024.1.
4
What is the exploitation method for CVE-2023-35188?
CVE-2023-35188 can be exploited through SQL injection requiring user authentication.
5
Is authentication required to exploit CVE-2023-35188?
Yes, CVE-2023-35188 requires user authentication for exploitation.