#VU51740 Security restrictions bypass in Orion Platform - CVE-2021-31475
Published: March 26, 2021 / Updated: May 26, 2021
Orion Platform
SolarWinds
Description
The vulnerability allows a remote administrator to execute arbitrary code on the server.
The vulnerability exists due to unspecified error within the Job Scheduler feature. A remote authenticated administrator can execute arbitrary code on the server.
Successful exploitation of the vulnerability requires knowledge of credentials of a low privileged local account on the Orion Server.