Home/Product/solarwinds orion platform
Product

solarwinds orion platform

49 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-23845
< 2023.3.1
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administra
6.8MEDIUM
CVE-2023-23840
< 2023.3.1
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administra
6.8MEDIUM
CVE-2022-47509
< 2023.2
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote ad
6.1MEDIUM
CVE-2022-47505
< 2023.2
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversa
7.8HIGH
CVE-2022-36963
< 2023.2
The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with
7.2HIGH
CVE-2023-23836
all versions
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allo
7.2HIGH
CVE-2022-47507
all versions
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Or
7.2HIGH
CVE-2022-47506
all versions
SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with aut
7.8HIGH
CVE-2022-47504
all versions
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Or
7.2HIGH
CVE-2022-47503
all versions
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Or
7.2HIGH
CVE-2022-38111
all versions
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Or
7.2HIGH
CVE-2022-36964
< 2020.2.6
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with va
8.8HIGH
CVE-2022-36962
< 2020.2.6
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over
7.2HIGH
CVE-2022-36960
< 2020.2.6
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access t
8.8HIGH
CVE-2022-38108
< 2020.2.6
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Or
7.2HIGH
CVE-2022-36966
< 2020.2.6
Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecu
5.4MEDIUM
CVE-2022-36958
< 2020.2.6
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with va
8.8HIGH
CVE-2022-36957
< 2020.2.6
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Or
7.2HIGH
CVE-2022-36961
<= 2022.2.0
A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privil
8.8HIGH
CVE-2021-35248
< 2020.2.6
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and thei
6.8MEDIUM
CVE-2021-35244
< 2020.2.6
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to wr
6.8MEDIUM
CVE-2021-35234
<= 2020.2.5
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An
8.0HIGH
CVE-2021-35218
< 2020.2.6
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker wh
8.9HIGH
CVE-2021-35215
<= 2020.2.5
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is r
8.9HIGH
CVE-2021-35238
<= 2020.2.5
User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
4.8MEDIUM
CVE-2021-35212
all versions
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean
8.9HIGH
CVE-2021-35240
<= 2020.2.5
A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they do not su
6.5MEDIUM
CVE-2021-35239
<= 2020.2.5
A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
7.5HIGH
CVE-2021-35213
<= 2020.2.5
An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.
8.9HIGH
CVE-2021-35222
< 2020.2.6
This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) fr
8.0HIGH
CVE-2021-35221
< 2020.2.6
Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from th
6.3MEDIUM
CVE-2021-35220
< 2020.2.6
Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
8.1HIGH
CVE-2021-35219
< 2020.2.6
ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Settings page
6.0MEDIUM
CVE-2021-28674
<= 2020.2.5
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside o
5.4MEDIUM
CVE-2021-27277
all versions
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastruct
7.8HIGH
CVE-2021-27258
all versions
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2
9.8CRITICAL
CVE-2021-3109
< 2020.2.5
The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context of an admi
4.8MEDIUM
CVE-2020-35856
< 2020.2.5
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
4.8MEDIUM
CVE-2020-27871
all versions
This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2
7.2HIGH
CVE-2020-27870
all versions
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platfor
6.5MEDIUM
CVE-2021-25275
< 2020.2.4
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and sto
7.8HIGH
CVE-2021-25274
< 2020.2.4
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions
9.8CRITICAL
CVE-2020-10148
all versions
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. Thi
9.8CRITICAL
CVE-2020-13169
< 2020.2.1
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before 2020.2.1 on multiple forms and pages. This
9.0CRITICAL
CVE-2019-12864
all versions
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error han
5.5MEDIUM
CVE-2019-12863
all versions
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console
4.8MEDIUM
CVE-2019-17127
all versions
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many app
6.1MEDIUM
CVE-2019-17125
all versions
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many
6.1MEDIUM
CVE-2019-9546
< 2018.4
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
9.8CRITICAL
threatengine.sh