The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
Advisories

No advisories yet.

Fixes

Solution

SolarWinds recommends that customers upgrade to SolarWinds Web Help Desk v12.8.3 HF2 as soon as it becomes available.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 08:15:00 +0900


Wed, 22 Oct 2025 05:30:00 +0900


Wed, 22 Oct 2025 04:30:00 +0900


Fri, 22 Nov 2024 21:00:00 +0900


Wed, 16 Oct 2024 22:30:00 +0900

Type Values Removed Values Added
First Time appeared Solarwinds web Help Desk
CPEs cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:-:*:*:*:*:*:*
cpe:2.3:a:solarwinds:web_help_desk:12.8.3:hotfix1:*:*:*:*:*:*
Vendors & Products Solarwinds web Help Desk

Wed, 16 Oct 2024 22:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 02:15:00 +0900

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2024-10-15'}


Thu, 26 Sep 2024 13:30:00 +0900

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds webhelpdesk
CPEs cpe:2.3:a:solarwinds:webhelpdesk:*:*:*:*:*:*:*:*
Vendors & Products Solarwinds
Solarwinds webhelpdesk
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 25 Aug 2024 08:30:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:solarwinds:webhelpdesk:*:*:*:*:*:*:*:*
Vendors & Products Solarwinds
Solarwinds webhelpdesk
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 23:30:00 +0900

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds webhelpdesk
CPEs cpe:2.3:a:solarwinds:webhelpdesk:*:*:*:*:*:*:*:*
Vendors & Products Solarwinds
Solarwinds webhelpdesk
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 06:30:00 +0900

Type Values Removed Values Added
Description The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
Title SolarWinds Web Help Desk Hardcoded Credential Vulnerability
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2025-10-21T22:55:46.764Z

Reserved: 2024-03-13T20:27:09.782Z

Link: CVE-2024-28987

cve-icon Vulnrichment

Updated: 2024-08-24T22:45:30.565Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-21T22:15:04.350

Modified: 2025-10-27T17:01:42.723

Link: CVE-2024-28987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses