Описание
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2024.3 (исключая)
cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00636
Низкий
7.6 High
CVSS3
8.3 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.6
github
больше 1 года назад
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.
EPSS
Процентиль: 70%
0.00636
Низкий
7.6 High
CVSS3
8.3 High
CVSS3
Дефекты
CWE-22