VYPR

NetPath

by SolarWinds

CVEs (3)

  • CVE-2019-12864MedMay 4, 2020
    risk 0.36cvss 5.5epss 0.00

    SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the…

  • CVE-2019-12954MedFeb 17, 2020
    risk 0.35cvss 5.4epss 0.01

    SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.

  • CVE-2019-12863MedFeb 25, 2020
    risk 0.31cvss 4.8epss 0.01

    SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.