ZDI-CAN-21894: ZDI-24-171: SolarWinds Orion Platform AppendUpdate SQL Injection Remote Code Execution Vulnerability
Published Feb 15, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Platform. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-50395.
Affected Software
1 affected component
SolarWinds Orion Platform
Event History
Feb 15, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21894?
The severity of ZDI-CAN-21894 has been assigned a CVSS rating of 8.8.
2
How do I fix ZDI-CAN-21894?
To fix ZDI-CAN-21894, update your SolarWinds Orion Platform to the latest version that addresses this vulnerability.
3
What types of attacks can occur due to ZDI-CAN-21894?
ZDI-CAN-21894 allows remote attackers to execute arbitrary code on affected installations.
4
Is authentication required to exploit ZDI-CAN-21894?
Yes, authentication is required to exploit the ZDI-CAN-21894 vulnerability.
5
Which software is affected by ZDI-CAN-21894?
The affected software is the SolarWinds Orion Platform.