Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. SolarWinds/
  3. SolarWinds Incident Response

SolarWinds Incident Response

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 100 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Incident response platform for alert management, collaboration, and remediation

by SolarWinds · solarwinds.com · source ↗

Known CVEs (100)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2021-25275 ↗HIGH 7.82021

    SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by …

  • CVE-2021-25274 ↗CRITICAL 9.82021

    The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients ca…

  • CVE-2020-35482 ↗MEDIUM 5.42021

    SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.

  • CVE-2020-35481 ↗CRITICAL 9.82021

    SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.

  • CVE-2020-28001 ↗MEDIUM 5.42021

    SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.

  • CVE-2020-27994 ↗MEDIUM 6.52021

    SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.

  • CVE-2019-16961 ↗MEDIUM 5.42021

    SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.

  • CVE-2019-16954 ↗MEDIUM 5.42021

    SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.

  • CVE-2019-16960 ↗MEDIUM 5.42021

    SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.

  • CVE-2019-16956 ↗MEDIUM 5.42021

    SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

  • CVE-2020-10148 ↗⚠ actively exploitedCRITICAL 9.82020

    The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication…

  • CVE-2019-16959 ↗MEDIUM 6.52020

    SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.

  • CVE-2019-16957 ↗MEDIUM 5.42020

    SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.

  • CVE-2019-16955 ↗MEDIUM 5.42020

    SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.

  • CVE-2020-25622 ↗HIGH 8.82020

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

  • CVE-2020-25621 ↗HIGH 8.42020

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys a…

  • CVE-2020-25620 ↗HIGH 7.82020

    An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] and [email protected]. These allow logins to th…

  • CVE-2020-25619 ↗MEDIUM 4.42020

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH feature (port forwardin…

  • CVE-2020-25618 ↗HIGH 8.82020

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as r…

  • CVE-2020-25617 ↗HIGH 8.82020

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), lea…

  • …and 80 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Security Orchestration, Automation & Response (SOAR) products

see all →
  • 7AI Platform · 7AI
  • AI EdgeLabs AI-Generated Playbooks · AI EdgeLabs
  • AIStrike BlueDome · AiStrike
  • ASPIA Infotech Security Workflow · ASPIA Infotech Pvt. Ltd.
  • Abusix Guardian Ops · Abusix
  • Agentic AI AR2™ · BluSapphire Cyber Systems Pvt Limited
  • Agentic Security Automation Platform · Blink Ops
  • Agents · Tines