HTTP: SolarWinds Firewall Security Manager userlogin.jsp Policy Bypass

A policy bypass vulnerability exists in SolarWinds Log and Event Manager. A successful attack could lead to a policy bypass condition on the server.

Extended Description

userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling.

Affected Products

Solarwinds firewall_security_manager

Short Name
HTTP:SOLARWINDS-POLICYBYPASS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Bypass CVE-2015-2284 Firewall Manager Policy Security SolarWinds userlogin.jsp
Release Date
03/20/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Solarwinds

CVSS Score

10.0

Found a potential security threat?