CVE-2024-28996: SolarWinds Platform SWQL Injection Vulnerability
Published Jun 4, 2024
·Updated
The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.
Affected Software
1 affected component
SolarWinds SolarWinds Platform<2024.2
Remediation
Information
SolarWinds recommends that customers upgrade to SolarWinds Platform 2024.2 as soon as it becomes available.
Event History
Jun 4, 2024
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
RemedyDescriptionSeverityWeakness
Jul 29, 56401
Event
via NVD·12:10 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-28996?
CVE-2024-28996 is classified as having a high attack complexity.
2
How do I fix CVE-2024-28996?
To remediate CVE-2024-28996, upgrade the SolarWinds Platform to version 2024.2 or later.
3
What is a SWQL Injection Vulnerability in the context of CVE-2024-28996?
A SWQL Injection Vulnerability allows attackers to manipulate SWQL queries, potentially leading to unauthorized access or data exposure.
4
Which versions of SolarWinds Platform are affected by CVE-2024-28996?
CVE-2024-28996 affects versions of the SolarWinds Platform prior to 2024.2.
5
Can CVE-2024-28996 be exploited remotely?
Yes, CVE-2024-28996 could potentially be exploited remotely due to its SWQL Injection nature.