← Vulnerability feed

Vulnerability record · CVE-2023-23838 · published 25 April 2023

CVE-2023-23838: Solarwinds database performance analyzer path traversal vulnerability

Solarwinds · Database Performance Analyzer

Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.

6.5 CVSS 3.1 Medium EPSS 1.3% · top 31.3% CWE-22 · Path traversal
6.5CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-23838 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-23837Solarwinds database performance analyzer error message information leak vulnerabilityNo exception handling vulnerability which revealed sensitive or excessive information to users.EPSS 0.81%7.5CVE-2022-38112Solarwinds database performance analyzer cleartext storage of sensitive data vulnerabilityIn DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.EPSS 0.42%6.4CVE-2025-26398Solarwinds database performance analyzer hard-coded credentials vulnerabilitySolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machin…EPSS 0.19%6.1CVE-2023-33231Solarwinds database performance analyzer cross-site scripting vulnerabilityXSS attack was possible in DPA 2023.2 due to insufficient input validationEPSS 0.50%6.1CVE-2021-35229Solarwinds database performance analyzer cross-site scripting vulnerabilityCross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL queryEPSS 3.2%6.1CVE-2018-19386Solarwinds database performance analyzer cross-site scripting vulnerabilitySolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is r…EPSS 9.0%5.4CVE-2022-38110Solarwinds database performance analyzer cross-site scripting vulnerabilityIn Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.EPSS 0.40%5.4CVE-2018-16243Solarwinds database performance analyzer cross-site scripting vulnerabilitySolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralM…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-23838), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.