Vulnerability Description
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Backup Profiler | < 5.1.2 |
| Solarwinds | Storage Manager | < 5.1.2 |
| Solarwinds | Storage Profiler | < 5.1.2 |
Related Weaknesses (CWE)
References
- http://www.exploit-db.com/exploits/18818ExploitThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/18833ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/51639Third Party AdvisoryVDB Entry
- http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72680Third Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/18818ExploitThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/18833ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/51639Third Party AdvisoryVDB Entry
- http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72680Third Party AdvisoryVDB Entry
FAQ
What is CVE-2012-2576?
CVE-2012-2576 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote att...
How severe is CVE-2012-2576?
CVE-2012-2576 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2012-2576?
Check the references section above for vendor advisories and patch information. Affected products include: Solarwinds Backup Profiler, Solarwinds Storage Manager, Solarwinds Storage Profiler.