Description
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.
Published: 2021-12-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Affected customers are advised to upgrade to 12.7.7 Hotfix 1 once it becomes available.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-21886 The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00552}

epss

{'score': 0.00462}


Subscriptions

Solarwinds Web Help Desk
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2024-09-16T17:18:45.942Z

Reserved: 2021-06-22T00:00:00.000Z

Link: CVE-2021-35243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-23T20:15:11.480

Modified: 2024-11-21T06:12:08.280

Link: CVE-2021-35243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses