Security Event Manager
by SolarWinds
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-0692 | Hig | 0.65 | 8.8 | 0.92 | Mar 1, 2024 | The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution. | ||
| CVE-2022-38114 | Med | 0.40 | 6.1 | 0.01 | Nov 23, 2022 | This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS. | ||
| CVE-2022-38115 | Med | 0.35 | 5.3 | 0.01 | Nov 23, 2022 | Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT | ||
| CVE-2022-38113 | Med | 0.35 | 5.3 | 0.01 | Nov 23, 2022 | This vulnerability discloses build and services versions in the server response header. |
- risk 0.65cvss 8.8epss 0.92
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.
- risk 0.40cvss 6.1epss 0.01
This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS.
- risk 0.35cvss 5.3epss 0.01
Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT
- risk 0.35cvss 5.3epss 0.01
This vulnerability discloses build and services versions in the server response header.