CVE-2014-9566

Summary

CVECVE-2014-9566
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2015-03-10 14:59:00 UTC
Updated2015-03-11 19:19:00 UTC
DescriptionMultiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager (IPAM) before 4.3, User Device Tracker (UDT) before 3.2, VoIP & Network Quality Manager (VNQM) before 4.2, Server & Application Manager (SAM) before 6.2, Web Performance Monitor (WPM) before 2.2, and possibly other Solarwinds products, allow remote authenticated users to execute arbitrary SQL commands via the (1) dir or (2) sort parameter to the (a) GetAccounts or (b) GetAccountGroups endpoint.

Risk And Classification

Problem Types: CWE-89

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Solarwinds Orion Ip Address Manager All All All All
Application Solarwinds Orion Netflow Traffic Analyzer All All All All
Application Solarwinds Orion Network Configuration Manager All All All All
Application Solarwinds Orion Network Performance Monitor All All All All
Application Solarwinds Orion Server And Application Manager All All All All
Application Solarwinds Orion User Device Tracker All All All All
Application Solarwinds Orion Voip Network Quality Manager All All All All
Application Solarwinds Orion Voip Network Quality Manager All All All All
Application Solarwinds Orion Web Performance Monitor All All All All

References

ReferenceSourceLinkTags
Solarwinds Orion Service - SQL Injection Vulnerabilities EXPLOIT-DB www.exploit-db.com Exploit
SolarWinds Network Performance Monitor Release Notes CONFIRM www.solarwinds.com Vendor Advisory
Volatile Minds: Authenticated Stacked SQL injection in core Solarwinds Orion service (CVE-2014-9566) MISC volatile-minds.blogspot.com Exploit
Solarwinds Core Orion Service SQL injection (CVE-2014-9566) by brandonprry · Pull Request #4836 · rapid7/metasploit-framework · GitHub MISC github.com
118746 OSVDB osvdb.org
Full Disclosure: Multiple SQL injections in core Orion service affecting many Solarwinds products (CVE-2014-9566) FULLDISC seclists.org Exploit
Solarwinds Orion Service SQL Injection ≈ Packet Storm MISC packetstormsecurity.com Exploit
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report