CVE-2022-36961: Orion Platform SQL Injection Privilege Escalation Vulnerability
A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-36961?
CVE-2022-36961 is a vulnerability in the SolarWinds Orion Platform that allows an authenticated attacker to perform SQL Injection and potentially escalate privileges or execute remote code.
How severe is CVE-2022-36961?
CVE-2022-36961 has a severity rating of 8.8 (High).
What is the affected software of CVE-2022-36961?
The affected software of CVE-2022-36961 is the SolarWinds Orion Platform with a version up to and inclusive of 2022.2.0.
How can an attacker exploit CVE-2022-36961?
An attacker can exploit CVE-2022-36961 by leveraging SQL Injection in an authenticated context to potentially escalate privileges or execute remote code.
Are there any references for CVE-2022-36961?
Yes, you can find more information about CVE-2022-36961 in the SolarWinds documentation and security advisories. Here are the references: - SolarWinds Documentation: [link1] - SolarWinds Security Advisories: [link2]