PT-2021-5156 · Solarwinds · Oroplatform
Chudypb
+1
·
Published
2021-05-05
·
Updated
2022-10-27
·
CVE-2021-35213
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Orion Platform version 2020.2.5
Description
An Improper Access Control Privilege Escalation issue was discovered in the User Setting of the Orion Platform. It allows a guest user to elevate privileges to the Administrator. Authentication is required to exploit this issue. The vulnerability is related to insufficient access control and insecure privilege management, which can be exploited by a remote attacker to gain administrator-level privileges.
Recommendations
For Orion Platform version 2020.2.5, consider disabling the SaveUserSetting component as a temporary workaround until a patch is available. Restrict access to the User Setting feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oroplatform