CVE-2014-9566

Scores

EPSS

0.775medium77.5%
0%20%40%60%80%100%

Percentile: 77.5%

CVSS

7.5high2.0
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager (IPAM) before 4.3, User Device Tracker (UDT) before 3.2, VoIP & Network Quality Manager (VNQM) before 4.2, Server & Application Manager (SAM) before 6.2, Web Performance Monitor (WPM) before 2.2, and possibly other Solarwinds products, allow remote authenticated users to execute arbitrary SQL commands via the (1) dir or (2) sort parameter to the (a) GetAccounts or (b) GetAccountGroups endpoint.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-89

Exploits

Exploit ID: 36262

Source: exploitdb

URL: https://www.exploit-db.com/exploits/36262

Vulnerable Software (8)

Type: Configuration

Vendor: solarwinds

Product: orion_ip_address_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:orion_ip_address_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "4.2",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: solarwinds

Product: orion_netflow_traffic_analyzer

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:orion_ip_address_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "4.2",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: solarwinds

Product: orion_network_configuration_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:orion_ip_address_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "4.2",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: solarwinds

Product: orion_network_performance_monitor

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:orion_ip_address_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "4.2",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: solarwinds

Product: orion_server_and_application_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:orion_ip_address_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "4.2",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: solarwinds

Product: orion_user_device_tracker

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:orion_ip_address_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "4.2",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: solarwinds

Product: orion_voip_&_network_quality_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:orion_ip_address_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "4.2",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: solarwinds

Product: orion_web_performance_monitor

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:orion_ip_address_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "4.2",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd