PT-2025-6168 · Solarwinds · Solarwinds Platform
Ravi Khanchani
+1
·
Published
2025-02-11
·
Updated
2025-02-12
·
CVE-2024-52611
CVSS v3.1
3.5
Low
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SolarWinds Platform versions 2024.4.1 and previous versions
Description:
The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. Although the disclosed data does not contain sensitive information, it could potentially assist an attacker in other malicious actions.
Recommendations:
For versions 2024.4.1 and previous versions, update to a version newer than 2024.4.1 to resolve the issue. As a temporary workaround, consider restricting access to error messages that could disclose potentially useful information to attackers.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Platform