RSS   Vulnerabilities for 'Orion platform'   RSS

2021-09-01
 
CVE-2021-35215

CWE-502
 

 
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

 
 
CVE-2021-35218

CWE-502
 

 
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server

 
 
CVE-2021-35238

CWE-79
 

 
User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.

 
2021-08-31
 
CVE-2021-35239

CWE-79
 

 
A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.

 
 
CVE-2021-35212

CWE-89
 

 
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.

 
 
CVE-2021-35219

CWE-668
 

 
ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Settings page.

 
 
CVE-2021-35220

CWE-77
 

 
Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.

 
2021-07-30
 
CVE-2021-28674

CWE-269
 

 
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the access control on Services/NodeManagement.asmx/DeleteObjNow is incorrect. To exploit this, an attacker must be authenticated and must have node management rights associated with at least one valid group on the platform.

 
2021-04-14
 
CVE-2021-27258

CWE-284
 

 
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.

 
2021-03-26
 
CVE-2021-3109

NVD-CWE-Other
 

 
The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context of an administrator account.

 


Copyright 2024, cxsecurity.com

 

Back to Top