Vulnerability Details CVE-2024-28074
                It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.002
                        
                    
                    
                        
                            EPSS Ranking 41.0%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 9.6
                        
                    
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2024-28074
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2019.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2020.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2021.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2022.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2022.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2023.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2023.2.0.73
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2023.2.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2023.2.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2023.2.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:2023.2.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:9.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:solarwinds:access_rights_manager:9.2