CVE-2025-40545: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in SolarWinds SolarWinds Observability Self-Hosted
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.
CVE-2025-40545: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in SolarWinds SolarWinds Observability Self-Hosted
Description
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- SolarWinds
- Date Reserved
- 2025-04-16T08:01:25.942Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 691c376d35a0ab0a562ec558
Added to database: 11/18/2025, 9:07:57 AM
Last updated: 11/18/2025, 9:08:16 AM
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2025-26391: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in SolarWinds SolarWinds Observability Self-Hosted
MediumCVE-2025-40549: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in SolarWinds Serv-U
CriticalCVE-2025-40548: CWE-269 Improper Privilege Management in SolarWinds Serv-U
CriticalCVE-2025-40547: CWE-116 Improper Encoding or Escaping of Output in SolarWinds Serv-U
CriticalCVE-2025-9625: CWE-352 Cross-Site Request Forgery (CSRF) in interledger Coil Web Monetization
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.