SolarWinds SFTP/SCP server through 2018-09-10 is...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 5, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
References