SolarWinds Security Update – 04 December 2023

SolarWinds has released a security update to fix a vulnerability in SolarWinds platform.

The addressed vulnerability could allow the attackers with low-privileged accounts to launch SQL injection attacks and then they could view, add, modify, or delete the data on the vulnerable system.

SQL Injection Remote Code Execution Vulnerability (CVE-2023-40056):

  • CVSS: 8
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Data Manipulation

Affected product:

  • SolarWinds platform 2023.4.1 and previous versions.
Vulnerabilities

CVE-2023-40056

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Update

References