SolarWinds Platform Affected by SWQL Injection Vulnerability
CVE-2024-28996

8.1HIGH

Key Information:

Vendor
Solarwinds
Vendor
CVE Published:
4 June 2024

Summary

The SolarWinds Platform is susceptible to an SWQL Injection vulnerability that could allow attackers to manipulate queries executed against the database. This vulnerability presents high attack complexity, which means that exploiting it requires a certain level of skill or access. The issue can potentially lead to unauthorized data access or system compromise, highlighting the importance of applying security updates promptly.

Affected Version(s)

SolarWinds Platform 2024.1.1 and previous versions

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nils Putnins from NATO
.