A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
References
Configurations
No configuration.
History
21 Nov 2024, 09:05
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US - | |
References | () https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072 - |
03 May 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-03 08:15
Updated : 2024-11-21 09:05
NVD link : CVE-2024-28072
Mitre link : CVE-2024-28072
CVE.ORG link : CVE-2024-28072
JSON object : View
Products Affected
No product.
CWE
CWE-532
Insertion of Sensitive Information into Log File