CVE ID | |
CVSS SCORE | 10.0, AV:N/AC:L/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
SolarWinds |
AFFECTED PRODUCTS |
Storage Resource Monitor |
TREND MICRO CUSTOMER PROTECTION | Trend Micro TippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID ['24359']. For further product information on the TippingPoint IPS: http://www.tippingpoint.com |
VULNERABILITY DETAILS |
The specific flaw exists within the RulesMetaData's addNewRule method which is reachable through the ScriptServlet servlet. The issue lies in the failure to sanitize user-supplied input prior to executing a SQL statement. An attacker could leverage this vulnerability to execute code under the context of the database, which defaults to SYSTEM. |
ADDITIONAL DETAILS |
SolarWinds has issued an update to correct this vulnerability. More details can be found at:
https://thwack.solarwinds.com/community/cloud-virtualization-storage_tht/storage-manager/blog/2016/06/10/srm-profiler-module-formerly-known-as-storage-manager-v623-hot-fix-1-is-available |
DISCLOSURE TIMELINE |
|
CREDIT | rgod |