SolarWinds Product Security Update Advisory

Overview

 

SolarWinds has released updates to fix vulnerabilities in their products. Users of affected versions are advised to update to the latest version.

 

Affected Products
 

CVE-2024-28074, CVE-2024-23475, CVE-2024-23474, CVE-2024-28993, CVE-2024-28992, CVE-2024-23466, CVE-2024-23472, CVE-2024-23470, CVE-2024-23465, CVE-2024-23468, CVE-2024-23471, CVE-2024-23469, CVE-2024-23467

  • SolarWinds Access Rights Manager (ARM) 2024.2 or below

 

 

Resolved Vulnerabilities

SolarWinds Access Rights Manager (ARM) Internal Deserialization Remote Code Execution Vulnerability (CVE-2024-28074)
SolarWinds Access Rights Manager (ARM) deleteTransferFile Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability (CVE-2024-23474)
SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerability (CVE-2024-23475, CVE-2024-28993, CVE-2024-28992, CVE-2024-23468)
SolarWinds Access Rights Manager Directory Traversal Remote Code Execution Vulnerability (CVE-2024-23466, CVE-2024-23467)
SolarWinds Access Rights Manager Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability (CVE-2024-23472)
Dangerous Method Remote Command Execution Vulnerability in SolarWinds Access Rights Manager (ARM) UserScriptHumster (CVE-2024-23470)
Critical Method Authentication Bypass Vulnerability in SolarWinds Access Rights Manager (ARM) ChangeHumster (CVE-2024-23465)
SolarWinds Access Rights Manager (ARM) CreateFile Directory Traversal Remote Code Execution Vulnerability in ChangeHumster (CVE-2024-23471)
Risky Method Remote Code Execution Vulnerability in SolarWinds Access Rights Manager (CVE-2024-23469)
 

 

Vulnerability Patches

 

Vulnerability Patches were made available in the latest update on July 18, 2024. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-28074, CVE-2024-23475, CVE-2024-23474, CVE-2024-28993, CVE-2024-28992, CVE-2024-23466, CVE-2024-23472, CVE-2024-23470, CVE-2024-23465, CVE-2024-23468, CVE-2024-23471, CVE-2024-23469, CVE-2024-23467

  • SolarWinds Access Rights Manager (ARM) version 2024.3

 

 

Referenced Sites

[1] CVE-2024-28074 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-28074

[2] CVE-2024-23475 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23475

[3] CVE-2024-23474 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23474

[4] CVE-2024-28993 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-28993

[5] CVE-2024-28992 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-28992

[6] CVE-2024-23466 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23466

[7] CVE-2024-23472 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-22372

[8] CVE-2024-23470 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23470

[9] CVE-2024-23465 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23465

[10] CVE-2024-23468 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23468

[11] CVE-2024-23471 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23471

[12] CVE-2024-23469 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23469

[13] CVE-2024-23467 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23467

[14] ARM 2024.3 release notes

https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm#link6