PT-2024-22664 · Solarwinds · Solarwinds Access Rights Manager

Chudypb

+1

·

Published

2024-07-17

·

Updated

2024-08-22

·

CVE-2024-28993

CVSS v3.1

8.3

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions SolarWinds Access Rights Manager (affected versions not specified)
Description The issue allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information due to a Directory Traversal and Information Disclosure vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28993

Affected Products

Solarwinds Access Rights Manager