SolarWinds Platform SWQL Injection Vulnerability
CVE-2024-29001

8HIGH

Key Information:

Vendor
Solarwinds
Vendor
CVE Published:
18 April 2024

Summary

A SWQL injection vulnerability exists within the user interface of the SolarWinds Platform, which necessitates authentication and user interaction for exploitation. This security flaw could potentially allow an attacker to manipulate SWQL queries executed by the application, leading to unauthorized access and compromised data integrity. Users of affected versions should remain vigilant and consider applying any available patches or updates as recommended in the official advisories to mitigate risks associated with this vulnerability.

Affected Version(s)

SolarWinds Platform 2024.1 and previous versions

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Jean-Michel Huguet & Arnoldas Radisauskas working with NATO
.