RSS   Vulnerabilities for 'Orion platform'   RSS

2020-02-25
 
CVE-2019-12863

CWE-74
 

 
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.

 
2020-01-17
 
CVE-2019-17127

CWE-79
 

 
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.

 
 
CVE-2019-17125

CWE-79
 

 
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.

 
2019-03-01
 
CVE-2019-9546

CWE-264
 

 
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.

 

 >>> Vendor: Solarwinds 33 Products
Tftp server
Orion network performance monitor
Ip address manager web interface
Network configuration manager
Log and event manager
Server and application monitor
Orion ip address manager
Orion netflow traffic analyzer
Orion network configuration manager
Orion server and application manager
Orion user device tracker
Orion voip & network quality manager
Orion web performance monitor
Firewall security manager
Storage manager
N-able n-central
Storage resource monitor
Virtualization manager
Ftp voyager
Log & event manager
Network performance monitor
Serv-u
Sftp/scp server
Orion platform
Serv-u ftp server
Damewire mini remote control
Database performance analyzer
Dameware mini remote control firmware
Dameware remote support
N-central
Netpath
Serv-u managed file transfer
Dameware


Copyright 2020, cxsecurity.com

 

Back to Top