CVE-2023-23845
- EPSS 0.29%
- Veröffentlicht 13.09.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:46:56
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
CVE-2023-23840
- EPSS 0.29%
- Veröffentlicht 13.09.2023 23:15:07
- Zuletzt bearbeitet 21.11.2024 07:46:55
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
CVE-2022-47509
- EPSS 0.81%
- Veröffentlicht 21.04.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:32:06
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.
CVE-2022-47505
- EPSS 0.06%
- Veröffentlicht 21.04.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:32:06
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.
CVE-2022-36963
- EPSS 0.74%
- Veröffentlicht 21.04.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 07:14:10
The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.
CVE-2023-23836
- EPSS 67.17%
- Veröffentlicht 15.02.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:46:55
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands....
CVE-2022-47507
- EPSS 11.28%
- Veröffentlicht 15.02.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:32:06
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
CVE-2022-47506
- EPSS 0.13%
- Veröffentlicht 15.02.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 07:32:06
SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default configuration, enabling the execution of arbitrary commands.
CVE-2022-47504
- EPSS 6.76%
- Veröffentlicht 15.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:32:06
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
CVE-2022-47503
- EPSS 6.76%
- Veröffentlicht 15.02.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:32:05
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.