ZDI-24-905: SolarWinds Access Rights Manager deleteTransferFile Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
Published Jul 18, 2024
·Updated
This vulnerability allows remote attackers to delete arbitrary files and disclose sensitive information on affected installations of SolarWinds Access Rights Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.6. The following CVEs are assigned: CVE-2024-28992.
Affected Software
1 affected component
SolarWinds Access Rights Manager
Event History
Jul 18, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-905?
The severity of ZDI-24-905 is rated at 8.6 on the CVSS scale.
2
How does ZDI-24-905 impact SolarWinds Access Rights Manager?
ZDI-24-905 allows remote attackers to delete arbitrary files and disclose sensitive information.
3
Is authentication required to exploit ZDI-24-905?
No, authentication is not required to exploit the ZDI-24-905 vulnerability.
4
What versions of SolarWinds Access Rights Manager are affected by ZDI-24-905?
All installations of SolarWinds Access Rights Manager are affected by ZDI-24-905.
5
What are the recommended mitigation steps for ZDI-24-905?
Users should apply any available patches and restrict access to the application to mitigate the risk of ZDI-24-905.