ZDI-23-1004: SolarWinds Orion Platform BlacklistedFilesChecker Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Platform. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1004?
ZDI-23-1004 has a high severity due to its potential for remote code execution on affected SolarWinds Orion Platform installations.
How do I fix ZDI-23-1004?
To fix ZDI-23-1004, it is recommended to apply the latest security patches released by SolarWinds for the Orion Platform.
Who can exploit the ZDI-23-1004 vulnerability?
ZDI-23-1004 can be exploited by authenticated attackers who have access to the affected SolarWinds Orion Platform.
What type of attacks can ZDI-23-1004 facilitate?
ZDI-23-1004 allows attackers to execute arbitrary code on affected installations of the SolarWinds Orion Platform.
Which versions of SolarWinds are affected by ZDI-23-1004?
ZDI-23-1004 affects all installations of the SolarWinds Orion Platform that are not patched against this vulnerability.