SolarWinds Orion IPAM Reflected Cross-site Scripting (CVE-2012-4939)
| Check Point Reference: | CPAI-2012-1335 | |
| Date Published: | ||
| Severity: | ||
| Source: | Security Focus Advisory 56342 | |
| Industry Reference(s): | CVE-2012-4939 |
|
| Protection Provided by: |
Security Gateway
|
|
|
Who is Vulnerable? SolarWinds Orion IPAM prior to v3.0-HotFix1 |
||
| Vulnerability Description A reflected cross-site scripting vulnerability exists in SolarWinds Orion IPAM. |
||
|
Vulnerability Details The vulnerability is due to insufficient sanitization of user-supplied input, which is echoed back to the user. A remote attacker could exploit this vulnerability by enticing an authenticated user to follow a crafted link. Successful exploitation could allow an attacker to execute script code in the browser security context of the Orion IPAM web interface. |
Protection Overview
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.