SolarWinds has issued a critical alert urging its customers to address a severe security flaw in its Web Help Desk software. The vulnerability, disclosed in an advisory on Tuesday and updated last Friday, involves a Java deserialization issue that can enable remote code execution. This flaw, identified as CVE-2024-28986, has been assigned a CVSS score of 9.8, indicating its high severity.
The Cybersecurity and Infrastructure Security Agency (CISA) included this CVE in its Known Exploited Vulnerabilities list on Thursday, highlighting its critical nature.
SolarWinds Web Help Desk, which is commonly used by small and medium-sized enterprises and organizations with remote employees, is affected. Despite the vulnerability being reported as unauthenticated, SolarWinds found through extensive testing that reproduction of the issue required prior authentication.
To mitigate potential risks, SolarWinds advises all users to apply the provided hotfix. However, they caution that if Security Assertion Markup Language (SAML) for single sign-on (SSO) is in use, users should hold off on the patch until a specific update addressing this scenario is released.
The vulnerability affects Web Help Desk versions 12.8.3 and earlier.



