Database Performance Analyzer

Vendor:

First CVE: Aug 14, 2019 · Active for 6 years

10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Database Performance Analyzer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2019
6 years ago
Most Recent CVE
Aug 12, 2025
347 days ago

CVE Severity & Scoring

Database Performance Analyzer10 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None4 (40.0%)
Unknown0 (0.0%)
Required6 (60.0%)
Privileges Required
Low3 (30.0%)
High1 (10.0%)
None6 (60.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the '
Aug 14, 20196.132NOYES
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
Jan 20, 20237.525NONO
No exception handling vulnerability which revealed sensitive or excessive information to users.
Apr 25, 20237.523NONO
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
Apr 21, 20226.123NONO
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack a
Aug 12, 20256.422NONO
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
Apr 25, 20236.522NONO
XSS attack was possible in DPA 2023.2 due to insufficient input validation
Jul 18, 20236.120NONO
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
Jan 20, 20235.420NONO
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.i
Dec 15, 20205.419NONO
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross sit
Oct 21, 20214.718NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Database Performance Analyzer

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2021.3.738814.70.6%00
12.0.307415.41.4%00
11.1.46815.41.4%00
11.1.45716.19.0%01