SolarWinds Product Security Update Advisory
Overview
SolarWinds has released updates to fix vulnerabilities in their products. Users of affected versions are advised to update to the latest version.
Affected Products
CVE-2024-28074, CVE-2024-23475, CVE-2024-23474, CVE-2024-28993, CVE-2024-28992, CVE-2024-23466, CVE-2024-23472, CVE-2024-23470, CVE-2024-23465, CVE-2024-23468, CVE-2024-23471, CVE-2024-23469, CVE-2024-23467
- SolarWinds Access Rights Manager (ARM) 2024.2 or below
Resolved Vulnerabilities
SolarWinds Access Rights Manager (ARM) Internal Deserialization Remote Code Execution Vulnerability (CVE-2024-28074)
SolarWinds Access Rights Manager (ARM) deleteTransferFile Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability (CVE-2024-23474)
SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerability (CVE-2024-23475, CVE-2024-28993, CVE-2024-28992, CVE-2024-23468)
SolarWinds Access Rights Manager Directory Traversal Remote Code Execution Vulnerability (CVE-2024-23466, CVE-2024-23467)
SolarWinds Access Rights Manager Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability (CVE-2024-23472)
Dangerous Method Remote Command Execution Vulnerability in SolarWinds Access Rights Manager (ARM) UserScriptHumster (CVE-2024-23470)
Critical Method Authentication Bypass Vulnerability in SolarWinds Access Rights Manager (ARM) ChangeHumster (CVE-2024-23465)
SolarWinds Access Rights Manager (ARM) CreateFile Directory Traversal Remote Code Execution Vulnerability in ChangeHumster (CVE-2024-23471)
Risky Method Remote Code Execution Vulnerability in SolarWinds Access Rights Manager (CVE-2024-23469)
Vulnerability Patches
Vulnerability Patches were made available in the latest update on July 18, 2024. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-28074, CVE-2024-23475, CVE-2024-23474, CVE-2024-28993, CVE-2024-28992, CVE-2024-23466, CVE-2024-23472, CVE-2024-23470, CVE-2024-23465, CVE-2024-23468, CVE-2024-23471, CVE-2024-23469, CVE-2024-23467
- SolarWinds Access Rights Manager (ARM) version 2024.3
Referenced Sites
[1] CVE-2024-28074 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-28074
[2] CVE-2024-23475 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23475
[3] CVE-2024-23474 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23474
[4] CVE-2024-28993 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-28993
[5] CVE-2024-28992 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-28992
[6] CVE-2024-23466 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23466
[7] CVE-2024-23472 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-22372
[8] CVE-2024-23470 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23470
[9] CVE-2024-23465 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23465
[10] CVE-2024-23468 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23468
[11] CVE-2024-23471 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23471
[12] CVE-2024-23469 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23469
[13] CVE-2024-23467 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-23467
[14] ARM 2024.3 release notes