The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.
Credits
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative