Back

CVE-2012-2576

CRITICAL

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

Published: Dec 20, 2017 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
solarwinds backup_profiler * < 5.1.2
solarwinds storage_manager * < 5.1.2
solarwinds storage_profiler * < 5.1.2

GitHub Security Advisory GHSA-m3hc-px32-r3pc

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2,...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 59.41%

Top 1% most likely to be exploited

Threat Score 57 / 100

Data Sources

NVD EPSS GitHub