SolarWinds Security Update – 05 December 2024

SolarWinds has released a security update to address a vulnerability affecting SolarWinds Platform 2024.4 and prior versions.

The addressed vulnerability could allow the attacker to perform a cross-site scripting attack and affect the user interface’s search and node information section.

SolarWinds Platform Cross Site Scripting Vulnerability (CVE-2024-45717):

  • CVSS: 7.0
  • Attack Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Cross Site Scripting
Vulnerabilities

CVE-2024-45717

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Advisory

References