VULNERABILITY INTELLIGENCE

CVE-2012-2576

CVSS score9.8 CRITICAL
EPSS probability59.41%
CISA KEVNot currently listed
Published2017-12-20
Last modified2026-06-16
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

Weakness classification

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Primary references