Vulnerability Description
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Database Performance Analyzer | 11.1.468 |
Related Weaknesses (CWE)
References
- https://gist.github.com/james-otten/d3ee2f0fccc3b87aafe1616a6c2c2d4eThird Party Advisory
- https://gist.github.com/james-otten/d3ee2f0fccc3b87aafe1616a6c2c2d4eThird Party Advisory
FAQ
What is CVE-2018-16243?
CVE-2018-16243 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, al...
How severe is CVE-2018-16243?
CVE-2018-16243 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-16243?
Check the references section above for vendor advisories and patch information. Affected products include: Solarwinds Database Performance Analyzer.