First published: Fri Sep 30 2022(Updated: )
A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Orion Platform | <=2022.2.0 |
All SolarWinds Platform customers are advised to upgrade to the latest generally available service update. (SolarWinds Platform)
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36961 is a vulnerability in the SolarWinds Orion Platform that allows an authenticated attacker to perform SQL Injection and potentially escalate privileges or execute remote code.
CVE-2022-36961 has a severity rating of 8.8 (High).
The affected software of CVE-2022-36961 is the SolarWinds Orion Platform with a version up to and inclusive of 2022.2.0.
An attacker can exploit CVE-2022-36961 by leveraging SQL Injection in an authenticated context to potentially escalate privileges or execute remote code.
Yes, you can find more information about CVE-2022-36961 in the SolarWinds documentation and security advisories. Here are the references: - SolarWinds Documentation: [link1] - SolarWinds Security Advisories: [link2]