ZeroHour

CVE-2021-35248

CVSS 3.1
4.3 medium
EPSS
<1%p57
Published
()
Modified
Description

It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.

Vendors
solarwinds
Products
orion platform
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.