It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-21891 It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
Fixes

Solution

This vulnerability has been fixed in Orion version 2020.2.6 HF3, customers are advised to upgrade to the latest version once it it is available.


Workaround

If you are unable to upgrade immediately. See SolarWinds Knowledgebase Article Below: https://support.solarwinds.com/SuccessCenter/s/article/Mitigate-the-Unrestricted-access-to-Orion-UserSettings-SWIS-entity-for-low-privilege-users-CVE-2021-35248

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00378}

epss

{'score': 0.00268}


Mon, 16 Sep 2024 20:15:00 +0000

Type Values Removed Values Added
Description It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings. It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2024-09-16T20:07:13.877Z

Reserved: 2021-06-22T00:00:00

Link: CVE-2021-35248

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-20T21:15:08.157

Modified: 2024-11-21T06:12:09.023

Link: CVE-2021-35248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.