ZDI-CAN-22697: ZDI-24-909: SolarWinds Access Rights Manager ExpandZipFile Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Access Rights Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2024-23467.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22697?
The severity of ZDI-CAN-22697 is rated 10.0 on the CVSS scale, indicating a critical vulnerability.
How do I fix ZDI-CAN-22697?
To fix ZDI-CAN-22697, apply the latest security patches provided by SolarWinds for Access Rights Manager.
What kind of attack can ZDI-CAN-22697 facilitate?
ZDI-CAN-22697 allows remote attackers to execute arbitrary code on affected installations without requiring authentication.
Which software is affected by ZDI-CAN-22697?
ZDI-CAN-22697 affects the SolarWinds Access Rights Manager software.
Is authentication required to exploit ZDI-CAN-22697?
No, authentication is not required to exploit the ZDI-CAN-22697 vulnerability.