Vulnerability record · CVE-2014-9566 · published 10 March 2015
CVE-2014-9566: SolarWinds Orion AccountManagement.asmx SQL injection via dir and sort parameters
Solarwinds · Orion Ip Address Manager
The Manage Accounts page in the AccountManagement.asmx service of the SolarWinds Orion Platform 2015.1 contains multiple SQL injection flaws in the dir and sort parameters of the GetAccounts and GetAccountGroups endpoints. The same service is used across many Orion modules (NPM, NTA, NCM, IPAM, UDT, VNQM, SAM, WPM), so the flaw has a broad footprint across the product line. It matters because a remote authenticated user can inject arbitrary SQL into the backend database.
Description
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager (IPAM) before 4.3, User Device Tracker (UDT) before 3.2, VoIP & Network Quality Manager (VNQM) before 4.2, Server & Application Manager (SAM) before 6.2, Web Performance Monitor (WPM) before 2.2, and possibly other Solarwinds products, allow remote authenticated users to execute arbitrary SQL commands via the (1) dir or (2) sort parameter to the (a) GetAccounts or (b) GetAccountGroups endpoint.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code is available and EPSS is very high, but exploitation requires a valid authenticated account, which limits reach compared with an unauthenticated flaw.
What it is
The Manage Accounts page in the AccountManagement.asmx service of the SolarWinds Orion Platform 2015.1 contains multiple SQL injection flaws in the dir and sort parameters of the GetAccounts and GetAccountGroups endpoints. The same service is used across many Orion modules (NPM, NTA, NCM, IPAM, UDT, VNQM, SAM, WPM), so the flaw has a broad footprint across the product line. It matters because a remote authenticated user can inject arbitrary SQL into the backend database.
Impact
An attacker with a valid account can execute arbitrary SQL commands against the Orion database, allowing read or modification of data and, depending on database privileges, further compromise of the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reached over the network through the AccountManagement.asmx web service endpoints GetAccounts and GetAccountGroups using the dir or sort parameter. The description states remote authenticated users, so a valid account is required; no user interaction is indicated.
Exploitation
Public exploit code exists, referenced by Exploit-DB, Packet Storm, Full Disclosure and a Metasploit pull request, and EPSS is 0.47749 (98.8th percentile). The CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Apply the SolarWinds Orion Platform 2015.1 update and the fixed module versions listed in the vendor release notes (NPM 11.5, NTA 4.1, NCM 7.3.2, IPAM 4.3, UDT 3.2, VNQM 4.2, SAM 6.2, WPM 2.2).
- Restrict network access to the Orion web service (AccountManagement.asmx) to trusted management networks only.
- Review and minimize accounts with access to the Manage Accounts page, and remove unused or stale Orion accounts.
- Run the Orion database account with least privilege so injected SQL cannot reach unrelated data or perform administrative operations.
- Monitor and alert on anomalous SQL error responses or unusual query patterns against the Orion database.
Detection
- Inspect web server and Orion logs for requests to AccountManagement.asmx with SQL metacharacters or stacked statements in the dir and sort parameters.
- Alert on repeated or malformed GetAccounts and GetAccountGroups requests from a single authenticated session.
- Monitor database logs for unexpected queries, errors or schema access originating from the Orion application account.
- Correlate authentication events on the Manage Accounts page with subsequent unusual database activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-9566 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9566), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.