Vulnerability Description
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Network Performance Monitor | <= 12.3 |
Related Weaknesses (CWE)
References
- https://labs.nettitude.com/blog/cve-2018-13442-solarwinds-npm-sql-injection/PatchThird Party Advisory
- https://labs.nettitude.com/blog/cve-2018-13442-solarwinds-npm-sql-injection/PatchThird Party Advisory
FAQ
What is CVE-2018-13442?
CVE-2018-13442 is a vulnerability with a CVSS score of 8.8 (HIGH). SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
How severe is CVE-2018-13442?
CVE-2018-13442 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-13442?
Check the references section above for vendor advisories and patch information. Affected products include: Solarwinds Network Performance Monitor.