ZDI-CAN-23062: ZDI-24-915: SolarWinds Access Rights Manager AddGeneratedReport Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
This vulnerability allows remote attackers to read and delete arbitrary files on affected installations of SolarWinds Access Rights Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2024-23472.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23062?
The severity of ZDI-CAN-23062 is rated 10.0 on the CVSS scale, indicating a critical vulnerability.
How do I fix ZDI-CAN-23062?
To fix ZDI-CAN-23062, apply the latest security patches and updates from SolarWinds for Access Rights Manager.
What type of attacks can be executed exploiting ZDI-CAN-23062?
Exploiting ZDI-CAN-23062 allows remote attackers to read and delete arbitrary files on affected installations without authentication.
Which software is affected by ZDI-CAN-23062?
ZDI-CAN-23062 affects SolarWinds Access Rights Manager installations.
Do I need authentication to exploit ZDI-CAN-23062?
No, authentication is not required to exploit ZDI-CAN-23062.