solarwinds orion-job-scheduler CVE-2021-31475 is a vulnerability in SolarWinds Orion Job Scheduler
Published on May 21, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authentication is required to exploit this vulnerability. The specific flaw exists within the JobRouterService WCF service. The issue is due to the WCF service configuration, which allows a critical resource to be accessed by unprivileged users. An attacker can leverage this vulnerability to execute code in the context of an administrator. Was ZDI-CAN-12007.

NVD

Weakness Type

Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. When a resource is given a permissions setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution or sensitive user data.


Products Associated with CVE-2021-31475

Want to know whenever a new CVE is published for SolarWinds Orion Job Scheduler? stack.watch will email you.

 

Affected Versions

SolarWinds Orion Job Scheduler Version 2020.2.1 HF 2 is affected by CVE-2021-31475

Exploit Probability

EPSS
12.28%
Percentile
93.78%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.