An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.
2021-08-31T17:15:07.910
2024-11-21T06:12:04.190
Modified
CVSSv3.1: 8.9 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | solarwinds | orion_platform | 2019.2 | Yes |
Application | solarwinds | orion_platform | 2019.4 | Yes |
Application | solarwinds | orion_platform | 2020.2.1 | Yes |
Application | solarwinds | orion_platform | 2020.2.4 | Yes |
Application | solarwinds | orion_platform | 2020.2.5 | Yes |