CVE-2023-23838

Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:solarwinds:database_performance_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:46

Type Values Removed Values Added
References () https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-2_release_notes.htm - Release Notes () https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-2_release_notes.htm - Release Notes
References () https://www.solarwinds.com/trust-center/security-advisories/cve-2023-23838 - Broken Link, Vendor Advisory () https://www.solarwinds.com/trust-center/security-advisories/cve-2023-23838 - Broken Link, Vendor Advisory

03 Aug 2023, 21:15

Type Values Removed Values Added
Summary Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.

04 May 2023, 19:32

Type Values Removed Values Added
References (MISC) https://www.solarwinds.com/trust-center/security-advisories/cve-2023-23838 - (MISC) https://www.solarwinds.com/trust-center/security-advisories/cve-2023-23838 - Broken Link, Vendor Advisory
References (MISC) https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-2_release_notes.htm - (MISC) https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-2_release_notes.htm - Release Notes
CPE cpe:2.3:a:solarwinds:database_performance_analyzer:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
CWE CWE-22
First Time Microsoft
Microsoft windows
Solarwinds database Performance Analyzer
Solarwinds
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

25 Apr 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-25 18:15

Updated : 2025-02-04 17:15


NVD link : CVE-2023-23838

Mitre link : CVE-2023-23838

CVE.ORG link : CVE-2023-23838


JSON object : View

Products Affected

solarwinds

  • database_performance_analyzer

microsoft

  • windows
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')