Unauthenticated RCE in SolarWinds Access Rights Manager via hardcoded static key
SolarWinds Access Rights Manager (ARM) contains an unauthenticated remote code execution flaw caused by a hardcoded static cryptographic key (CWE-321). An attacker who can reach the ARM service from an adjacent network, as reflected in the CVSS attack vector, can abuse the static key to bypass authentication and execute code without any user interaction or credentials. Successful exploitation yields high-impact code execution on the ARM server, which typically holds privileged Active Directory and service credentials, creating significant lateral-movement risk. Organizations running ARM on-premises, most commonly mid-size and large enterprises managing file-server and AD permissions, are affected. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there are no confirmed reports of exploitation in the wild.
· SolarWinds Access Rights Managermoderate
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability.
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
· solarwinds web help desk—
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover.
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
· solarwinds serv-u—
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator.
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
· solarwinds serv-u—
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution.
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
· solarwinds serv-u—
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation.
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
· solarwinds serv-u—
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with t
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
· solarwinds serv-u—
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts.
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
· solarwinds serv-u—
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privil
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
· solarwinds serv-u—
—