Описание
Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.
Ссылки
- Vendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2020.2.6 (включая)
Одно из
cpe:2.3:a:solarwinds:network_performance_monitor:*:*:*:*:*:*:*:*
cpe:2.3:a:solarwinds:network_performance_monitor:2020.2.6:hotfix1:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01106
Низкий
5 Medium
CVSS3
6.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 6.4
github
больше 3 лет назад
Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.
EPSS
Процентиль: 77%
0.01106
Низкий
5 Medium
CVSS3
6.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo