Known Vulnerabilities for Database Performance Analyzer by Solarwinds
Listed below are 9 of the newest known vulnerabilities associated with "Database Performance Analyzer" by "Solarwinds".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-33231 json | XSS attack was possible in DPA 2023.2 due to insufficient input validation | 6.1 - MEDIUM | 2023-07-18 | 2023-08-03 |
| CVE-2023-23838 json | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | 6.5 - MEDIUM | 2023-04-25 | 2023-08-03 |
| CVE-2023-23837 json | No exception handling vulnerability which revealed sensitive or excessive information to users. | 7.5 - HIGH | 2023-04-25 | 2023-08-03 |
| CVE-2022-38112 json | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. | 7.5 - HIGH | 2023-01-20 | 2023-09-14 |
| CVE-2022-38110 json | In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflec... | 5.4 - MEDIUM | 2023-01-20 | 2023-08-03 |
| CVE-2021-35229 json | Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a ... | 6.1 - MEDIUM | 2022-04-21 | 2022-05-03 |
| CVE-2021-35228 json | This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on ... | 4.7 - MEDIUM | 2021-10-21 | 2021-10-26 |
| CVE-2018-19386 json | SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where... | 6.1 - MEDIUM | 2019-08-14 | 2019-08-27 |
| CVE-2018-16243 json | SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to... | 5.4 - MEDIUM | 2020-12-15 | 2020-12-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solarwinds | Database Performance Analyzer | 12.0.3074 | |||
| Application | Solarwinds | Database Performance Analyzer | 11.1.468 | |||
| Application | Solarwinds | Database Performance Analyzer | 11.1.457 |