CVE-2018-16243: SolarWinds Database Performance Analyzer

Medium severity, CVSS 5.4. EPSS: 1.4% chance of exploitation in the next 30 days.

SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.

Affected products

  • SolarWinds Database Performance Analyzer: version 11.1.468 only; version 12.0.3074 only

Published 2020-12-15. Last modified 2026-06-17.