CVE-2014-5504
Summary
| CVE | CVE-2014-5504 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-09-04 17:55:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via unspecified vectors, related to HyperSQL. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solarwinds | Log And Event Manager | 5.2.0 | All | All | All |
| Application | Solarwinds | Log And Event Manager | 5.4.0 | All | All | All |
| Application | Solarwinds | Log And Event Manager | 5.5.0 | All | All | All |
| Application | Solarwinds | Log And Event Manager | 5.6.0 | All | All | All |
| Application | Solarwinds | Log And Event Manager | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| SolarWinds Log & Event Manager Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.solarwinds.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.