SolarWinds Orion API authentication bypass allows remote comand execution

Discussion in 'other security issues & news' started by guest, Dec 26, 2020.

  1. guest

    guest Guest

    SolarWinds Orion API authentication bypass allows remote comand execution
    Vulnerability Note VU#843464
    December 26, 2020
    https://kb.cert.org/vuls/id/843464
     
  2. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Here's an interesting little bit: SolarWinds is owned by Thoma Bravo holdings it seems. The same corp. that owns Sophos, a majority stake in McAfee and a whole bunch of others. Good thing it has all those assets; prob. there are-- or will be-- lawsuits stemming from that breach.

    Thoma Bravo Portfolio Companies

    Apologies if this has been posted already elsewhere.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.