Back to Database
Status published
Critical
CVE-2019-9546
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation...
Vulnerability Description
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-9546
Credits & Attribution
No credits recorded in the NVD database.
References
- https://support.solarwinds.com/Success_Center/Orion_Platform/Orion_Documentation/Additional_Resources/Orion_Platform_2018-4_Hotfix_2
- https://support.solarwinds.com/SuccessCenter/s/article/CVE-2019-9546-Orion-Platform-Vulnerability
- https://github.com/active-labs/Advisories/blob/master/2019/ACTIVE-2019-005.md
More from solarwinds
View All →CVE-2022-47012
Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips...
Unknown
0
CVE-2021-3154
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated...
High
7.5
CVE-2021-3109
The custom menu item options page in SolarWinds Orion Platform...
Medium
4.8
CVE-2021-32604
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail...
Medium
5.4
CVE-2021-31217
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file...
Critical
9.1
Affected Vendor
solarwinds
View all reports →Affected Software
orion platform
Vulnerable Versions:
0, 2018.4
Timeline
Official Publish:
March 1st, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.