Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.
Solution:
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://documentation.solarwinds.com/en/success_center/patchman/content/release_notes/patchman_2020-2-6_release_notes.htm | release notes vendor advisory |
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35216 | patch vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-1246/ | vdb entry third party advisory |