📦 Access Rights Manager

by Solarwinds

🔍 What is Access Rights Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-28991

CRITICAL CVSS 9.0 Sep 12, 2024

SolarWinds Access Rights Manager (ARM) contains a deserialization vulnerability (CWE-502) that allows authenticated users to execute arbitrary code remotely. This affects organizations using vulnerabl...

CVE-2024-23475

CRITICAL CVSS 9.6 Jul 17, 2024

CVE-2024-23475 is a critical directory traversal vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to delete arbitrary files and access sensitive information. Thi...

CVE-2024-23471

CRITICAL CVSS 9.6 Jul 17, 2024

This vulnerability allows authenticated users of SolarWinds Access Rights Manager to execute arbitrary code remotely by exploiting improper authentication mechanisms. Organizations running vulnerable ...

CVE-2024-23466

CRITICAL CVSS 9.6 Jul 17, 2024

This vulnerability allows unauthenticated attackers to traverse directories and execute arbitrary code with SYSTEM privileges on SolarWinds Access Rights Manager. All organizations running vulnerable ...

CVE-2024-23469

CRITICAL CVSS 9.6 Jul 17, 2024

SolarWinds Access Rights Manager (ARM) has a critical remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges. This affects all organ...

CVE-2024-28075

CRITICAL CVSS 9.0 May 14, 2024

This vulnerability allows authenticated users of SolarWinds Access Rights Manager to execute arbitrary code remotely on affected systems. Attackers with valid credentials can exploit this deserializat...

CVE-2024-23479

CRITICAL CVSS 9.6 Feb 15, 2024

SolarWinds Access Rights Manager (ARM) contains a directory traversal vulnerability that allows unauthenticated attackers to execute arbitrary code remotely. This affects all organizations running vul...

CVE-2024-23476

CRITICAL CVSS 9.6 Feb 15, 2024

SolarWinds Access Rights Manager (ARM) contains a directory traversal vulnerability that allows unauthenticated attackers to execute arbitrary code remotely. This affects organizations using vulnerabl...

CVE-2024-28992

HIGH CVSS 7.6 Jul 17, 2024

CVE-2024-28992 is a directory traversal and information disclosure vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to delete arbitrary files and access sensitiv...

CVE-2024-23474

HIGH CVSS 7.6 Jul 17, 2024

CVE-2024-23474 is a vulnerability in SolarWinds Access Rights Manager that allows attackers to delete arbitrary files and disclose sensitive information. This affects organizations using vulnerable ve...

CVE-2024-23468

HIGH CVSS 7.6 Jul 17, 2024

CVE-2024-23468 is a directory traversal vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to delete arbitrary files and access sensitive information. This affects...

CVE-2024-23473

HIGH CVSS 8.6 May 14, 2024

This CVE describes a hard-coded credential vulnerability in SolarWinds Access Rights Manager that allows authentication bypass to the RabbitMQ management console. Attackers can exploit this to gain un...

CVE-2024-23478

HIGH CVSS 8.0 Feb 15, 2024

SolarWinds Access Rights Manager (ARM) contains a deserialization vulnerability that allows authenticated users to execute arbitrary code remotely. This affects organizations using vulnerable versions...

CVE-2023-35182

HIGH CVSS 8.8 Oct 19, 2023

CVE-2023-35182 is a remote code execution vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to execute arbitrary code on the ARM server. This affects organization...

CVE-2023-35184

HIGH CVSS 8.8 Oct 19, 2023

CVE-2023-35184 is a remote code execution vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to execute arbitrary code on affected systems. This affects organizati...

CVE-2023-35186

HIGH CVSS 8.0 Oct 19, 2023

This vulnerability allows authenticated users of SolarWinds Access Rights Manager to execute arbitrary code remotely by abusing SolarWinds services. It affects organizations using vulnerable versions ...

CVE-2023-35180

HIGH CVSS 8.0 Oct 19, 2023

CVE-2023-35180 is a remote code execution vulnerability in SolarWinds Access Rights Manager that allows authenticated users to execute arbitrary code by abusing the ARM API. This affects organizations...

CVE-2024-28990

MEDIUM CVSS 6.3 Sep 12, 2024

SolarWinds Access Rights Manager (ARM) contains hard-coded credentials that allow authentication bypass to the RabbitMQ management console. This vulnerability affects all SolarWinds ARM installations ...