CVE-2023-23838

Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:solarwinds:database_performance_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

03 Aug 2023, 21:15

Type Values Removed Values Added
Summary Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.

04 May 2023, 19:32

Type Values Removed Values Added
CPE cpe:2.3:a:solarwinds:database_performance_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
First Time Solarwinds database Performance Analyzer
Solarwinds
Microsoft windows
Microsoft
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-2_release_notes.htm - (MISC) https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-2_release_notes.htm - Release Notes
References (MISC) https://www.solarwinds.com/trust-center/security-advisories/cve-2023-23838 - (MISC) https://www.solarwinds.com/trust-center/security-advisories/cve-2023-23838 - Broken Link, Vendor Advisory

25 Apr 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-25 18:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-23838

Mitre link : CVE-2023-23838

CVE.ORG link : CVE-2023-23838


JSON object : View

Products Affected

solarwinds

  • database_performance_analyzer

microsoft

  • windows
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')