{
    "id": "CVE-2012-2576",
    "published": "2017-12-20 21:29:00",
    "last_modified": "2026-06-16 23:41:42",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-89",
    "description": "SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.",
    "epss_score": "0.59413",
    "epss_percentile": "0.99094",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:22:14",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "solarwinds",
            "product": "backup_profiler"
        },
        {
            "vendor": "solarwinds",
            "product": "storage_manager"
        },
        {
            "vendor": "solarwinds",
            "product": "storage_profiler"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "18818",
            "title": "SolarWinds Storage Manager 5.1.0 - Remote SYSTEM SQL Injection",
            "date": "2012-05-01",
            "url": "https://www.exploit-db.com/exploits/18818"
        }
    ],
    "refs_list": [
        "http://www.exploit-db.com/exploits/18818",
        "http://www.exploit-db.com/exploits/18833",
        "http://www.securityfocus.com/bid/51639",
        "http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotes/vulnerability.htm",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/72680",
        "http://www.exploit-db.com/exploits/18818",
        "http://www.exploit-db.com/exploits/18833",
        "http://www.securityfocus.com/bid/51639",
        "http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotes/vulnerability.htm",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/72680"
    ]
}