Medium severity6.8NVD Advisory· Published Dec 20, 2021· Updated Jun 17, 2026
CVE-2021-35248
CVE-2021-35248
Description
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6(expand)+ 1 more
- (no CPE)
- (no CPE)range: 2020.2.6 HF 2 and previous versions
cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*range: <2020.2.6
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- documentation.solarwinds.com/en/Success_Center/orionplatform/content/core-secure-configuration.htmnvdVendor Advisory
- support.solarwinds.com/SuccessCenter/s/article/Orion-Platform-2020-2-6-Hotfix-3nvdRelease NotesVendor Advisory
- www.solarwinds.com/trust-center/security-advisories/CVE-2021-35248nvdVendor Advisory
News mentions
0No linked articles in our index yet.