SolarWinds Security Updates – 21 July 2024

SolarWinds has released security updates to address several vulnerabilities affecting SolarWinds Access Rights Manager.

information, bypass security restrictions, or execute arbitrary code and gain access to the affected system by sending a specially crafted request.

Sample of the addressed vulnerabilities:

1. SolarWinds Access Rights Manager Remote Code Execution Vulnerability (CVE-2024-23469):

  • CVSS: 9.6
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. SolarWinds Access Rights Manager Security Bypass Vulnerability (CVE-2024-23465):

  • CVSS: 8.3
  • Attack Vector: Adjacent Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Updates

References