Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21868 | Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination. |
Solution
SolarWinds recommends upgrading to the latest version of Network Performance Monitor 2020.2.6 Hotfix 2 as soon as it becomes available. All customers should review and implement all of the recommendations from the Orion Secure Configuration Guide
Workaround
In the mentioned workaround, Customers can restrict the viewing of access rights for non-admin users via Orion UI. \nhttps://support.solarwinds.com/SuccessCenter/s/article/Orion-NPM-NetPath-account-limitations?language=en_US
No history.
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-09-17T00:11:06.373Z
Reserved: 2021-06-22T00:00:00
Link: CVE-2021-35225
No data.
Status : Modified
Published: 2021-10-21T18:15:09.880
Modified: 2024-11-21T06:12:05.900
Link: CVE-2021-35225
No data.
OpenCVE Enrichment
No data.
EUVD