CVE-2024-28986

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
13/08/2024
Last modified:
27/10/2025

Description

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. <br /> <br /> While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.  <br /> <br /> However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:* 12.8.2 (including)
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:*