Home
MEDIUM: 4.8 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
affected
SolarWinds Observability Self-Hosted 2025.4 and prior versions
affected
Description
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
SolarWinds Observability Self-Hosted 2025.4 and prior versions
Credits
Frédéric Goossens
References
www.solarwinds.com/...ter/security-advisories/CVE-2025-40545
documentation.solarwinds.com/...o_2025-4-1_release_notes.htm