PT-2024-4875 · Solarwinds · Solarwinds Access Rights Manager

Published

2024-01-23

·

Updated

2024-09-10

·

CVE-2024-28074

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SolarWinds Access Rights Manager (affected versions not specified)
Description: The issue is related to the createGlobalServerChannelInternal method in SolarWinds Access Rights Manager, which has weaknesses in its deserialization mechanism. This can be exploited by a remote attacker to execute arbitrary code. It was discovered that a previous vulnerability was not completely fixed, and despite some controls being implemented, a researcher was able to bypass these and exploit the vulnerability using a different method.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2024-05399
CVE-2024-28074
ZDI-24-906

Affected Products

Solarwinds Access Rights Manager