Permissions, Privileges, and Access Controls in Orion Platform - CVE-2021-35244
Published: December 21, 2021
Orion Platform
SolarWinds
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to application does not properly impose security restrictions. A remote user with Orion alert management rights can use this vulnerability to perform an unrestricted file upload causing a remote code execution.