Описание
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
Ссылки
- Vendor Advisory
- Release NotesVendor Advisory
- Not ApplicableVendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Release NotesVendor Advisory
- Not ApplicableVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Одновременно
Одно из
EPSS
6.8 Medium
CVSS3
7.2 High
CVSS3
8.5 High
CVSS2
Дефекты
Связанные уязвимости
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
Уязвимость реализации компонента управления «Log alert to a file» программного обеспечения сетевого мониторинга SolarWinds Orion Platform, позволяющая нарушителю повысить свои привилегии или выполнить произвольный код
EPSS
6.8 Medium
CVSS3
7.2 High
CVSS3
8.5 High
CVSS2