Directory traversal and file enumeration vulnerability: Database Performance Analyzer (DPA) 2023.1
CVE-2023-23838
6.5MEDIUM
Key Information:
- Vendor
- Solarwinds
- Vendor
- CVE Published:
- 25 April 2023
Summary
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
Affected Version(s)
Database Performance Analyzer Windows 2022.3 and previous versions
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved