CVE-2019-12864
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/05/2020
Last modified:
21/07/2021
Description
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:solarwinds:netpath:1.1.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:solarwinds:network_performance_monitor:12.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:solarwinds:orion_platform:2018.4:hotfix3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page