Database Performance Analyzer
by SolarWinds
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23837 | Hig | 0.49 | 7.5 | 0.01 | Apr 25, 2023 | No exception handling vulnerability which revealed sensitive or excessive information to users. | ||
| CVE-2022-38112 | Hig | 0.49 | 7.5 | 0.00 | Jan 20, 2023 | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. | ||
| CVE-2021-35229 | Med | 0.44 | 6.8 | 0.03 | Apr 21, 2022 | Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query | ||
| CVE-2023-23838 | Med | 0.42 | 6.5 | 0.01 | Apr 25, 2023 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | ||
| CVE-2018-19386 | Med | 0.40 | 6.1 | 0.09 | Aug 14, 2019 | SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI. | ||
| CVE-2025-26398 | Med | 0.36 | 5.6 | 0.00 | Aug 12, 2025 | SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local… | ||
| CVE-2022-38110 | Med | 0.35 | 5.4 | 0.00 | Jan 20, 2023 | In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting. | ||
| CVE-2018-16243 | Med | 0.35 | 5.4 | 0.01 | Dec 15, 2020 | SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen. |
- risk 0.49cvss 7.5epss 0.01
No exception handling vulnerability which revealed sensitive or excessive information to users.
- risk 0.49cvss 7.5epss 0.00
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
- risk 0.44cvss 6.8epss 0.03
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
- risk 0.42cvss 6.5epss 0.01
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
- risk 0.40cvss 6.1epss 0.09
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
- risk 0.36cvss 5.6epss 0.00
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local…
- risk 0.35cvss 5.4epss 0.00
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
- risk 0.35cvss 5.4epss 0.01
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.