CVE-2021-35212
31.08.2021, 17:15
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.
Vendor | Product | Version |
---|---|---|
solarwinds | orion_platform | 2019.2 |
solarwinds | orion_platform | 2019.4 |
solarwinds | orion_platform | 2020.2.1 |
solarwinds | orion_platform | 2020.2.4 |
solarwinds | orion_platform | 2020.2.5 |
𝑥
= Vulnerable software versions
References