Description
Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted data.
No analysis available yet.
Remediation
Vendor Solution
SolarWinds recommends upgrading to both the latest version of Patch Manager and Orion Integration Module as soon as it becomes available.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 16 Sep 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Deserialization of untrusted data causing Remote code execution vulnerability. | Insecure Deserialization of untrusted data causing Remote code execution vulnerability. |
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-09-16T20:58:13.615Z
Reserved: 2021-06-22T00:00:00.000Z
Link: CVE-2021-35217
No data.
Status : Modified
Published: 2021-09-08T14:15:12.117
Modified: 2024-11-21T06:12:04.887
Link: CVE-2021-35217
No data.
OpenCVE Enrichment
No data.
Weaknesses