| CVE ID | |
| CVSS SCORE | 6.8, AV:L/AC:L/Au:S/C:C/I:C/A:C |
| AFFECTED VENDORS |
SolarWinds |
| AFFECTED PRODUCTS |
Server and Application Monitor |
| VULNERABILITY DETAILS |
The specific flaw exists within the Alert Manager component. Alerts within this component can be configured in a way that allows for the execution of arbitrary scripts or programs. An attacker can leverage this to elevate privileges and execute code in the context of NT Authority\SYSTEM. |
| ADDITIONAL DETAILS |
09/04/2014 - ZDI disclosed to the vendor -- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the service to trusted users.
|
| DISCLOSURE TIMELINE |
|
| CREDIT | Tom McCredie - tom.mac@hp.com |