« Volver al listado

Solarwinds

Solarwinds Database Performance Analyzer: vulnerabilidades y CVE

Solarwinds Database Performance Analyzer tiene 11 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses1
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-28322Media (5.6)0.39%—30 jun 2026
SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
CVE-2025-26398Media (6.4)0.19%—12 ago 2025
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability…
CVE-2023-33231Media (6.1)0.50%—18 jul 2023
XSS attack was possible in DPA 2023.2 due to insufficient input validation
CVE-2023-23838Media (6.5)1.3%—25 abr 2023
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
CVE-2023-23837Alta (7.5)0.81%—25 abr 2023
No exception handling vulnerability which revealed sensitive or excessive information to users.
CVE-2022-38112Alta (7.5)0.42%—20 ene 2023
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
CVE-2022-38110Media (5.4)0.40%—20 ene 2023
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
CVE-2021-35229Media (6.1)3.2%—21 abr 2022
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
CVE-2021-35228Media (4.7)0.58%—21 oct 2021
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would…
CVE-2018-16243Media (5.4)1.4%—15 dic 2020
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc,…
CVE-2018-19386Media (6.1)9.0%—14 ago 2019
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a…

Otros productos de Solarwinds