SolarWinds Database Performance Analyzer
By the Year
In 2024 there have been 0 vulnerabilities in SolarWinds Database Performance Analyzer . Last year Database Performance Analyzer had 3 security vulnerabilities published. Right now, Database Performance Analyzer is on track to have less security vulnerabilities in 2024 than it did last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 0 | 0.00 |
2023 | 3 | 6.33 |
2022 | 1 | 6.10 |
2021 | 1 | 4.70 |
2020 | 1 | 5.40 |
2019 | 1 | 6.10 |
2018 | 0 | 0.00 |
It may take a day or so for new Database Performance Analyzer vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent SolarWinds Database Performance Analyzer Security Vulnerabilities
XSS attack was possible in DPA 2023.2 due to insufficient input validation
CVE-2023-33231
6.1 - Medium
- July 18, 2023
XSS attack was possible in DPA 2023.2 due to insufficient input validation
XSS
In DPA 2022.4 and older releases
CVE-2022-38112
7.5 - High
- January 20, 2023
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
Cleartext Storage of Sensitive Information
In Database Performance Analyzer (DPA) 2022.4 and older releases
CVE-2022-38110
5.4 - Medium
- January 20, 2023
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
XSS
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
CVE-2021-35229
6.1 - Medium
- April 21, 2022
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
XSS
This vulnerability occurred due to missing input sanitization for one of the output fields
CVE-2021-35228
4.7 - Medium
- October 21, 2021
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim.
XSS
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities
CVE-2018-16243
5.4 - Medium
- December 15, 2020
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
XSS
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component
CVE-2018-19386
6.1 - Medium
- August 14, 2019
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for SolarWinds Database Performance Analyzer or by SolarWinds? Click the Watch button to subscribe.