VulnerabilityModified
CVE-2018-16243
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and…
MEDIUM 5.4EPSS 1.38%
Does this matter?
Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.
Description
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.38% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- solarwinds/database performance analyzer
- Source
- cve@mitre.org
References
- https://gist.github.com/james-otten/d3ee2f0fccc3b87aafe1616a6c2c2d4eThird Party Advisory
- https://gist.github.com/james-otten/d3ee2f0fccc3b87aafe1616a6c2c2d4eThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.