HTTP: SolarWinds Storage Manager AuthenticationFilter Authentication Bypass

SolarWinds Storage Manager suffers from authentication bypass vulnerability. Successful exploitation could result in code execution under the context of the system.

Extended Description

The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors.

Affected Products

Solarwinds storage_manager

Short Name
HTTP:SOLARWINDS-AUTH-BYPASS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Authentication AuthenticationFilter Bypass CVE-2015-5371 Manager SolarWinds Storage bid:69438 bid:75515
Release Date
11/24/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3675
False Positive
Unknown
Vendors

Solarwinds

CVSS Score

10.0

Found a potential security threat?