Home
HIGH: 8.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HDefault status
affected
previous versions (2024.3)
affected
Description
The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin access within the Active Directory environment.
Problem types
CWE-287 Improper Authentication
Product status
previous versions (2024.3)
Credits
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
References
documentation.solarwinds.com/...arm_2024-3_release_notes.htm
documentation.solarwinds.com/...arm_2024-3_release_notes.htm