8.8

CVE-2022-36960

SolarWinds Platform Improper Input Validation

SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Solarwinds ≫ Orion Platform Version < 2020.2.6
Solarwinds ≫ Orion Platform Version 2020.2.6 Update -
Solarwinds ≫ Orion Platform Version 2020.2.6 Update hotfix1
Solarwinds ≫ Orion Platform Version 2020.2.6 Update hotfix2
Solarwinds ≫ Orion Platform Version 2020.2.6 Update hotfix3
Solarwinds ≫ Orion Platform Version 2020.2.6 Update hotfix4
Solarwinds ≫ Orion Platform Version 2020.2.6 Update hotfix5
Solarwinds ≫ Orion Platform Version 2022.2
Solarwinds ≫ Orion Platform Version 2022.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.89% 0.546
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@solarwinds.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm
Vendor Advisory
Release Notes
https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36960
Vendor Advisory