ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.
http://www.zerodayinitiative.com/advisories/ZDI-15-460
http://www.solarwinds.com/documentation/srm/docs/releasenotes/releasenotes.htm