CVE-2023-40058: Sensitive Information Disclosure Vulnerability
Published Dec 21, 2023
·Updated
Sensitive data was added to our public-facing knowledgebase that, if exploited, could be used to access components of Access Rights Manager (ARM) if the threat actor is in the same environment.
Affected Software
1 affected component
SolarWinds Access Rights Manager<=2023.2.1
Remediation
Information
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.2
Event History
Dec 21, 2023
CVE Published
04:14 PM
Data Sourced
04:14 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-40058?
CVE-2023-40058 has been classified as a significant security vulnerability due to the potential exposure of sensitive data.
2
How do I fix CVE-2023-40058?
To fix CVE-2023-40058, update your SolarWinds Access Rights Manager software to version 2023.2.2 or later.
3
Who is affected by CVE-2023-40058?
CVE-2023-40058 affects users of SolarWinds Access Rights Manager versions up to and including 2023.2.1.
4
What type of vulnerability is CVE-2023-40058?
CVE-2023-40058 is a sensitive data exposure vulnerability.
5
What are the potential risks of CVE-2023-40058?
The potential risks of CVE-2023-40058 include unauthorized access to components of Access Rights Manager by an attacker in the same environment.