Executive brief
SolarWinds Web Help Desk is vulnerable to Java Deserialization, which can lead to Remote Code Execution (RCE) on the host machine. While initially reported as an unauthenticated vulnerability, the vendor suggests authentication may be required, though they recommend patching all instances regardless. The vulnerability is confirmed to have been exploited in the wild.
Affected products
- SolarWinds Web Help Desk Up to and including 12.8.2, and 12.8.3 before Hotfix 1
Timeline
- 2024-08-13: disclosed: Initial CVE entry received from SolarWinds
- 2024-08-15: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2024-08-15: advisory: NVD publication date
- 2024-09-05: other: CISA due date for remediation