VYPR
Medium severity6.8NVD Advisory· Published Dec 20, 2021· Updated Jun 17, 2026

CVE-2021-35248

CVE-2021-35248

Description

It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • SolarWinds/Orion NPMllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 2020.2.6 HF 2 and previous versions
  • cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*range: <2020.2.6
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.