SB2021100201 - Information disclosure in SolarWinds Pingdom



SB2021100201 - Information disclosure in SolarWinds Pingdom

Published: October 2, 2021 Updated: November 2, 2021

Security Bulletin ID SB2021100201
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2021-35214)

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected application fails to invalidate user session upon password or email address change. An attacker with physical access can change a password or email address without terminating the user session during multiple active browser sessions.


Remediation

Install update from vendor's website.