← Vulnerability feed

Vulnerability record · CVE-2021-35229 · published 21 April 2022

CVE-2021-35229: Solarwinds database performance analyzer cross-site scripting vulnerability

Solarwinds · Database Performance Analyzer

Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query

6.1 CVSS 3.1 Medium EPSS 3.2% · top 12.4% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35229 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-23837Solarwinds database performance analyzer error message information leak vulnerabilityNo exception handling vulnerability which revealed sensitive or excessive information to users.EPSS 0.81%7.5CVE-2022-38112Solarwinds database performance analyzer cleartext storage of sensitive data vulnerabilityIn DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.EPSS 0.42%6.5CVE-2023-23838Solarwinds database performance analyzer path traversal vulnerabilityDirectory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.EPSS 1.3%6.4CVE-2025-26398Solarwinds database performance analyzer hard-coded credentials vulnerabilitySolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machin…EPSS 0.19%6.1CVE-2023-33231Solarwinds database performance analyzer cross-site scripting vulnerabilityXSS attack was possible in DPA 2023.2 due to insufficient input validationEPSS 0.50%6.1CVE-2018-19386Solarwinds database performance analyzer cross-site scripting vulnerabilitySolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is r…EPSS 9.0%5.4CVE-2022-38110Solarwinds database performance analyzer cross-site scripting vulnerabilityIn Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.EPSS 0.40%5.4CVE-2018-16243Solarwinds database performance analyzer cross-site scripting vulnerabilitySolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralM…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-35229), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.