CVE-2022-36960: SolarWinds Platform Improper Input Validation
Published Nov 29, 2022
·Updated
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.
Affected Software
9 affected components
SolarWinds Orion Platform<2020.2.6
SolarWinds Orion Platform=2020.2.6
SolarWinds Orion Platform=2020.2.6-hotfix1
SolarWinds Orion Platform=2020.2.6-hotfix2
SolarWinds Orion Platform=2020.2.6-hotfix3
SolarWinds Orion Platform=2020.2.6-hotfix4
SolarWinds Orion Platform=2020.2.6-hotfix5
SolarWinds Orion Platform=2022.2
SolarWinds Orion Platform=2022.3
Remediation
Information
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2022.4
Event History
Nov 29, 2022
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-36960.
2
What is the severity of CVE-2022-36960?
The severity of CVE-2022-36960 is high with a severity value of 8.8.
3
What software is affected by CVE-2022-36960?
SolarWinds Orion Platform versions 2020.2.6 and later, including versions 2022.2 and 2022.3, are affected by CVE-2022-36960.
4
How does CVE-2022-36960 impact SolarWinds Platform?
CVE-2022-36960 allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.
5
Are there any available fixes or patches for CVE-2022-36960?
It is recommended to refer to SolarWinds' documentation and security advisories for available fixes and patches for CVE-2022-36960.