9
CVSSv2

CVE-2021-35212

Published: 31/08/2021 Updated: 05/11/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An SQL injection Privilege Escalation Vulnerability exists in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds orion platform 2019.2

solarwinds orion platform 2019.4

solarwinds orion platform 2020.2.1

solarwinds orion platform 2020.2.4

solarwinds orion platform 2020.2.5