5.4

CVE-2022-36966

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SolarwindsOrion Platform Version < 2020.2.6
SolarwindsOrion Platform Version2020.2.6 Update-
SolarwindsOrion Platform Version2020.2.6 Updatehotfix1
SolarwindsOrion Platform Version2020.2.6 Updatehotfix2
SolarwindsOrion Platform Version2020.2.6 Updatehotfix3
SolarwindsOrion Platform Version2020.2.6 Updatehotfix4
SolarwindsOrion Platform Version2020.2.6 Updatehotfix5
SolarwindsOrion Platform Version2022.2
SolarwindsOrion Platform Version2022.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.546
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
psirt@solarwinds.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.