Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
Solution:
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-2_release_notes.htm | release notes |
https://www.solarwinds.com/trust-center/security-advisories/cve-2023-23838 | vendor advisory broken link |