It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25241 | It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability. |
Fixes
Solution
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2024.3
Workaround
No workaround given by the vendor.
References
History
Tue, 10 Sep 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solarwinds
Solarwinds access Rights Manager |
|
| CPEs | cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Solarwinds
Solarwinds access Rights Manager |
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-08-02T00:48:48.255Z
Reserved: 2024-03-01T08:53:44.513Z
Link: CVE-2024-28074
Updated: 2024-08-02T00:48:48.255Z
Status : Modified
Published: 2024-07-17T15:15:13.417
Modified: 2024-11-21T09:05:45.503
Link: CVE-2024-28074
No data.
OpenCVE Enrichment
No data.
EUVD