CVE-2023-40056: SolarWinds Platform SQL Injection Remote Code Execution Vulnerability
Published Nov 28, 2023
·Updated
SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.
Affected Software
1 affected component
SolarWinds SolarWinds Platform<2023.4.2
Remediation
Information
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.4.2
Event History
Nov 28, 2023
CVE Published
05:51 PM
Data Sourced
05:51 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-40056?
CVE-2023-40056 is a SQL Injection Remote Code Execution vulnerability found in the SolarWinds Platform.
2
How severe is CVE-2023-40056?
CVE-2023-40056 has a severity value of 8, which is considered high.
3
Who is affected by CVE-2023-40056?
Any SolarWinds Platform user with a low privileged account is affected by CVE-2023-40056.
4
How can CVE-2023-40056 be exploited?
CVE-2023-40056 can be exploited through SQL Injection with a low privileged account.
5
How can I fix CVE-2023-40056?
To fix CVE-2023-40056, apply the necessary updates and patches provided by SolarWinds.