CVE-2024-28991: SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28991?
CVE-2024-28991 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-28991?
To mitigate CVE-2024-28991, upgrade SolarWinds Access Rights Manager to version 2024.3.1 or later.
Who is affected by CVE-2024-28991?
CVE-2024-28991 affects authenticated users of SolarWinds Access Rights Manager prior to version 2024.3.1.
What impact does CVE-2024-28991 have if exploited?
If exploited, CVE-2024-28991 allows an authenticated user to execute arbitrary code on the server.
Is there a workaround for CVE-2024-28991?
Currently, the recommended approach to address CVE-2024-28991 is to apply the security update rather than relying on a workaround.