peter bassill · operator
$ cve CVE-2014-9566 JSON

CVE-2014-9566 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 47.7% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager (IPAM) before 4.3, User Device Tracker (UDT) before 3.2, VoIP & Network Quality Manager (VNQM) before 4.2, Server & Application Manager (SAM) before 6.2, Web Performance Monitor (WPM) before 2.2, and possibly other Solarwinds products, allow remote authenticated users to execute arbitrary SQL commands via the (1) dir or (2) sort parameter to the (a) GetAccounts or (b) GetAccountGroups endpoint.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS47.75% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2015-03-10
Last modified2026-06-17

Affected (8)

VendorProduct
solarwindsorion ip address manager
solarwindsorion netflow traffic analyzer
solarwindsorion network configuration manager
solarwindsorion network performance monitor
solarwindsorion server and application manager
solarwindsorion user device tracker
solarwindsorion voip \& network quality manager
solarwindsorion web performance monitor

Public exploits

SourceTitleDate
exploit-dbSolarWinds Orion Service - SQL Injection2015-03-04

References

→ the Explorer  ·  watch your stack  ·  NVD