ZDI-CAN-23061: ZDI-24-916: SolarWinds Access Rights Manager AddReportResult Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
This vulnerability allows remote attackers to read and delete arbitrary files on affected installations of SolarWinds Access Rights Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2024-23475.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23061?
The severity of ZDI-CAN-23061 is rated at 10.0 on the CVSS scale, indicating critical impact.
How do I fix ZDI-CAN-23061?
To fix ZDI-CAN-23061, apply the latest security patches or updates provided by SolarWinds for Access Rights Manager.
Which software is affected by ZDI-CAN-23061?
ZDI-CAN-23061 affects SolarWinds Access Rights Manager installations.
Can ZDI-CAN-23061 be exploited without authentication?
Yes, ZDI-CAN-23061 can be exploited without any authentication required.
What are the consequences of exploiting ZDI-CAN-23061?
Exploiting ZDI-CAN-23061 allows remote attackers to read and delete arbitrary files on affected installations.