ZDI-CAN-21895: ZDI-24-170: SolarWinds Orion Platform AppendCreatePrimary SQL Injection Remote Code Execution Vulnerability
Published Feb 15, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Platform. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-35188.
Affected Software
1 affected component
SolarWinds Orion Platform
Event History
Feb 15, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21895?
ZDI-CAN-21895 has been assigned a CVSS rating of 8.8, indicating high severity.
2
How do I fix ZDI-CAN-21895?
To fix ZDI-CAN-21895, update to the latest patched version of the SolarWinds Orion Platform.
3
What type of attacks can be executed due to ZDI-CAN-21895?
ZDI-CAN-21895 allows remote attackers to execute arbitrary code on affected installations.
4
Is authentication required to exploit ZDI-CAN-21895?
Yes, authentication is required to exploit the ZDI-CAN-21895 vulnerability.
5
What software is affected by ZDI-CAN-21895?
The affected software by ZDI-CAN-21895 is the SolarWinds Orion Platform.