Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted data.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
SolarWinds recommends upgrading to both the latest version of Patch Manager and Orion Integration Module as soon as it becomes available.
Workaround
No workaround given by the vendor.
References
History
Mon, 16 Sep 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Deserialization of untrusted data causing Remote code execution vulnerability. | Insecure Deserialization of untrusted data causing Remote code execution vulnerability. |
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-09-16T20:58:13.615Z
Reserved: 2021-06-22T00:00:00
Link: CVE-2021-35217
No data.
Status : Modified
Published: 2021-09-08T14:15:12.117
Modified: 2024-11-21T06:12:04.887
Link: CVE-2021-35217
No data.
OpenCVE Enrichment
No data.