CVE ID | |
CVSS SCORE | 6.8, AV:L/AC:L/Au:S/C:C/I:C/A:C |
AFFECTED VENDORS |
SolarWinds |
AFFECTED PRODUCTS |
Server and Application Monitor |
VULNERABILITY DETAILS |
The specific flaw exists within the Alert Manager component. Alerts within this component can be configured in a way that allows for the execution of arbitrary scripts or programs. An attacker can leverage this to elevate privileges and execute code in the context of NT Authority\SYSTEM. |
ADDITIONAL DETAILS |
09/04/2014 - ZDI disclosed to the vendor -- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the service to trusted users.
|
DISCLOSURE TIMELINE |
|
CREDIT | Tom McCredie - tom.mac@hp.com |