Network Management

Reporting SolarWinds product security issues and vulnerabilities

This article covers how to report security and product vulnerability issues that point to Solarwinds products.

First published date

10/29/2018 12:53 PM

Last published date

9/28/2023 3:37 PM

Overview

This article describes suggested actions to address a security issue in your SolarWinds product software. 

Product section

Orion Platform

Cause

This relates to all SolarWinds Products

Resolution

While all SolarWinds products are thoroughly tested by our product development teams, additional updates (such as a hotfix) may be released throughout the year to address unforeseen vulnerabilities that appear in our products. 

The SolarWinds development teams test all products for vulnerabilities prior to release. To ensure that your corporate enterprise is protected from vulnerabilities and unauthorized access, ensure that all SolarWinds and non-SolarWinds software applications in your enterprise are running the latest release with all associated patches and hotfixes.


Locating fixed and current issues 

Log in to the Customer Portal to access the product release notes for a list of fixed and current issues. The thwack community also provides additional product information, as well as current issues. 


Upgrading your software 

If you are not running the latest SolarWinds product release, check the product in the Customer Portal to see if a hotfix addressed your issue. For the latest product security updates, SolarWinds suggests upgrading your software to the latest releases and patches. 


Reporting current issues 

If you run an audit and discover any vulnerabilities in our products, submit a ticket for SolarWinds Technical Support and include details about the issue and your system for our product development team. Your case will be validated and handed over to our Security Team for tracking and will work with you directly on this matter.


Security at SolarWinds 

SolarWinds is committed to taking our customer's security and privacy concerns seriously and makes it a priority. We strive to implement and maintain security processes, procedures, standards, and take all reasonable care to prevent unauthorized access to our customer data. We apply appropriate administrative, operational, and technical security controls to help ensure that our customer data is handled and processed in a responsible and secure manner.

Our security strategy covers all aspects of our business, including:

  • Corporate security policies
  • Organizational security
  • Physical and environmental security
  • Operational security processes and procedures
  • Incident management and response
  • Business continuity and disaster recovery
  • Data protection


Security Documents 


Want to report a security concern? 

SolarWinds reviews all reports of security vulnerabilities submitted to it affecting SolarWinds products and services. To report a vulnerability in one of our products or solutions or a vulnerability in one of our corporate websites, please contact our Product Security Incident Response Team (PSIRT) at psirt@solarwinds.com