PT-2023-27244 · Solarwinds · Solarwinds Platform

CVE-2023-40061

·

Publicado

2023-11-01

·

Atualizado

2023-12-28

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SolarWinds Platform version 2023.4
Description The issue is related to an insecure job execution mechanism, which can lead to other attacks. This vulnerability may result in Denial of Service (DoS) or Cross-Site Scripting (XSS) attacks.
Recommendations For SolarWinds Platform version 2023.4, update to a version that includes the fix for the insecure job execution mechanism vulnerability. As a temporary workaround, consider restricting access to the job execution mechanism to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40061

Produtos afetados

Solarwinds Platform