CVE-2024-28988 (CNNVD-202509-027)
中文标题:
SolarWinds Web Help Desk 代码问题漏洞
英文标题:
SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability
漏洞描述
中文描述:
SolarWinds Web Help Desk是美国SolarWinds公司的一套服务台和资产管理软件。该软件支持集中式知识库、IT资产管理、项目和任务管理等功能。 SolarWinds Web Help Desk 12.8.3 HF2版本及之前版本存在代码问题漏洞,该漏洞源于Java反序列化问题,可能导致远程代码执行。
英文描述:
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research. We recommend all Web Help Desk customers apply the patch, which is now available. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| SolarWinds | Web Help Desk | 12.8.3 HF 2 and previous versions | - | - |
cpe:2.3:a:solarwinds:web_help_desk:12.8.3_hf_2_and_previous_versions:*:*:*:*:*:*:*
|
| solarwinds | web_help_desk | * | - | - |
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*
|
| solarwinds | web_help_desk | 12.8.3 | - | - |
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2024-28988 |
2025-11-11 15:22:30 | 2025-11-11 07:39:15 |
| NVD | nvd_CVE-2024-28988 |
2025-11-11 15:00:21 | 2025-11-11 07:47:15 |
| CNNVD | cnnvd_CNNVD-202509-027 |
2025-11-11 15:12:55 | 2025-11-11 08:00:09 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 1 -> 3
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-202509-027
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']