Check Point Reference: | CPAI-2012-1335 |
Date Published: | 3 Mar 2013 |
Severity: | Medium |
Last Updated: | Thursday 09 January, 2025 |
Source: | CVE-2012-4939 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | SolarWinds Orion IPAM prior to v3.0-HotFix1 |
Vulnerability Description | A reflected cross-site scripting vulnerability exists in SolarWinds Orion IPAM. |
Vulnerability Details | The vulnerability is due to insufficient sanitization of user-supplied input, which is echoed back to the user. A remote attacker could exploit this vulnerability by enticing an authenticated user to follow a crafted link. Successful exploitation could allow an attacker to execute script code in the browser security context of the Orion IPAM web interface. |
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: Web Client Enforcement Violation
Attack Information: SolarWinds Orion IPAM Reflected Cross-site Scripting