CVE-2019-12864
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the…
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-209
- Affected
- solarwinds/netpath · solarwinds/network performance monitor · solarwinds/orion platform
- Source
- cve@mitre.org
References
- https://www.esecforte.com/network-performance-monitor-india-esec-forte-technologies/Exploit, Third Party Advisory
- https://www.solarwinds.com/network-performance-monitorVendor Advisory
- https://www.esecforte.com/network-performance-monitor-india-esec-forte-technologies/Exploit, Third Party Advisory
- https://www.solarwinds.com/network-performance-monitorVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.