SolarWinds has addressed a significant security flaw in its Web Help Desk platform, which could permit attackers to circumvent SAML-based authentication This article explores solarwinds supports tls. . The issue received a critical CVSS score of 9.8 from the security researcher Dhabaleshwar Das, who responsibly reported it.

SAML, or Security Assertion Markup Language, is often used by organizations to connect applications with centralized identity providers like Microsoft Entra ID, Okta, and Active Directory Federation Services (ADFS). Depending on the account context and application permissions, this could expose sensitive information such as help desk tickets, user data, internal communications, IT asset information, and other operational details managed through the platform.

Help desk portals are typically accessible by employees, contractors, and external users, making them prime targets for attackers aiming to gain initial access or sensitive internal data. The update also addresses multiple third-party pgAdmin vulnerabilities, including remote code execution, command injection, LDAP injection, and TLS certificate validation bypass issues. SolarWinds now supports only TLS 1.2/1.3, enforces HTTPS, applies security headers, restricts internal services to local access, and removes server version details from responses.

Customers relying on this method are advised to plan a migration to either SAML 2.0 or HTTP Header authentication, ensuring the newly deployed Single Sign-On (SSO) configuration is thoroughly tested and secured with the latest patches.