Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2017-7647] SolarWinds Log & Event Manager - Arbitrary Command Injection

bishopfox.com | vulnerability | CVE-2017-7647 | #advisory | #solarwinds | #command-injection | #cve-2017-7647 | #lem

Summary

Advisory for an arbitrary command injection in SolarWinds Log & Event Manager (CVE-2017-7647): an authenticated user could escape the CMC console and run commands as root; fixed in 6.3.1 HF4.
Published
Collected

original ↗

Related coverage

back