Description
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
In plain language
AI Worth attentionSolarWinds Database Performance Analyzer 11.1.457 can be used to show a fake or unsafe link to a user who opens an attacker-supplied page, so small businesses using this version should have IT investigate.
Reflected XSS in the idcStateError component reflects the page parameter into the “Try Again” button HREF, requiring user interaction to trigger.
What to do now
- Check whether you run SolarWinds Database Performance Analyzer 11.1.457.
- Ask your IT provider or SolarWinds whether a supported update fixes CVE-2018-19386; no fixed version is currently available in the findings.
- Until confirmed, warn users not to open unexpected Database Performance Analyzer links, especially links that lead to an error page.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-19386 and every CVE in our database. Create a free account — no credit card required.
Create Free Account