VYPR

DPA

by SolarWinds

CVEs (3)

  • CVE-2022-38112HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.00

    In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.

  • CVE-2023-33231MedJul 18, 2023
    risk 0.40cvss 6.1epss 0.01

    XSS attack was possible in DPA 2023.2 due to insufficient input validation

  • CVE-2021-35228MedOct 21, 2021
    risk 0.36cvss 5.5epss 0.01

    This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change…