Access Restriction bypass vulnerability via referrer spoof - Business Logic Bypass
Vulnerability Description
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-32076
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- SolarWinds would like to thank Moaaz Taha for reporting on the issue in a responsible manner.
More from SolarWinds
View All →Affected Vendor
SolarWinds
View all reports →