Vulnerability Description
ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Storage Manager | <= 6.1 |
Related Weaknesses (CWE)
References
- http://www.solarwinds.com/documentation/srm/docs/releasenotes/releasenotes.htmVendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-15-460
- http://www.solarwinds.com/documentation/srm/docs/releasenotes/releasenotes.htmVendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-15-460
FAQ
What is CVE-2015-7838?
CVE-2015-7838 is a vulnerability with a CVSS score of 10.0 (HIGH). ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.
How severe is CVE-2015-7838?
CVE-2015-7838 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7838?
Check the references section above for vendor advisories and patch information. Affected products include: Solarwinds Storage Manager.