Another Critical RCE Flaw Discovered in SolarWinds Orion Platform

Read the original article: Another Critical RCE Flaw Discovered in SolarWinds Orion Platform


IT infrastructure management provider SolarWinds on Thursday released a new update to its Orion networking monitoring tool with fixes for four security vulnerabilities, counting two weaknesses that could be exploited by an authenticated attacker to achieve remote code execution (RCE).
Chief among them is a JSON deserialization flaw that allows an authenticated user to execute arbitrary code via


Read the original article: Another Critical RCE Flaw Discovered in SolarWinds Orion Platform