← Vulnerability feed

Vulnerability record · CVE-2014-9566 · published 10 March 2015

CVE-2014-9566: SolarWinds Orion AccountManagement.asmx SQL injection via dir and sort parameters

Solarwinds · Orion Ip Address Manager

The Manage Accounts page in the AccountManagement.asmx service of the SolarWinds Orion Platform 2015.1 contains multiple SQL injection flaws in the dir and sort parameters of the GetAccounts and GetAccountGroups endpoints. The same service is used across many Orion modules (NPM, NTA, NCM, IPAM, UDT, VNQM, SAM, WPM), so the flaw has a broad footprint across the product line. It matters because a remote authenticated user can inject arbitrary SQL into the backend database.

7.5 CVSS 2.0 High EPSS 48% · top 1.2% CWE-89 · SQL injection
7.5CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
14References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager (IPAM) before 4.3, User Device Tracker (UDT) before 3.2, VoIP & Network Quality Manager (VNQM) before 4.2, Server & Application Manager (SAM) before 6.2, Web Performance Monitor (WPM) before 2.2, and possibly other Solarwinds products, allow remote authenticated users to execute arbitrary SQL commands via the (1) dir or (2) sort parameter to the (a) GetAccounts or (b) GetAccountGroups endpoint.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityPublic exploit code is available and EPSS is very high, but exploitation requires a valid authenticated account, which limits reach compared with an unauthenticated flaw.

What it is

The Manage Accounts page in the AccountManagement.asmx service of the SolarWinds Orion Platform 2015.1 contains multiple SQL injection flaws in the dir and sort parameters of the GetAccounts and GetAccountGroups endpoints. The same service is used across many Orion modules (NPM, NTA, NCM, IPAM, UDT, VNQM, SAM, WPM), so the flaw has a broad footprint across the product line. It matters because a remote authenticated user can inject arbitrary SQL into the backend database.

Impact

An attacker with a valid account can execute arbitrary SQL commands against the Orion database, allowing read or modification of data and, depending on database privileges, further compromise of the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

Reached over the network through the AccountManagement.asmx web service endpoints GetAccounts and GetAccountGroups using the dir or sort parameter. The description states remote authenticated users, so a valid account is required; no user interaction is indicated.

Exploitation

Public exploit code exists, referenced by Exploit-DB, Packet Storm, Full Disclosure and a Metasploit pull request, and EPSS is 0.47749 (98.8th percentile). The CVE is not listed in CISA KEV and no ransomware use is documented.

What to do

  • Apply the SolarWinds Orion Platform 2015.1 update and the fixed module versions listed in the vendor release notes (NPM 11.5, NTA 4.1, NCM 7.3.2, IPAM 4.3, UDT 3.2, VNQM 4.2, SAM 6.2, WPM 2.2).
  • Restrict network access to the Orion web service (AccountManagement.asmx) to trusted management networks only.
  • Review and minimize accounts with access to the Manage Accounts page, and remove unused or stale Orion accounts.
  • Run the Orion database account with least privilege so injected SQL cannot reach unrelated data or perform administrative operations.
  • Monitor and alert on anomalous SQL error responses or unusual query patterns against the Orion database.

Detection

  • Inspect web server and Orion logs for requests to AccountManagement.asmx with SQL metacharacters or stacked statements in the dir and sort parameters.
  • Alert on repeated or malformed GetAccounts and GetAccountGroups requests from a single authenticated session.
  • Monitor database logs for unexpected queries, errors or schema access originating from the Orion application account.
  • Correlate authentication events on the Manage Accounts page with subsequent unusual database activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9566 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-8917Solarwinds orion network performance monitor vulnerabilitySolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes…EPSS 36%8.8CVE-2020-14005Solarwinds orion network performance monitor vulnerabilitySolarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a de…EPSS 14%6.8CVE-2012-2602Solarwinds orion network performance monitor cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers…EPSS 6.0%5.4CVE-2020-14006Solarwinds orion network performance monitor cross-site scripting vulnerabilitySolarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.EPSS 1.1%5.4CVE-2020-14007Solarwinds orion network performance monitor cross-site scripting vulnerabilitySolarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.EPSS 1.1%4.3CVE-2012-4939Solarwinds ip address manager web interface cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance…EPSS 7.2%4.3CVE-2012-2577Solarwinds orion network performance monitor cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inj…EPSS 10%4.3CVE-2010-4828Solarwinds orion network performance monitor cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbit…EPSS 5.1%

Source: NIST National Vulnerability Database (record CVE-2014-9566), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.