First published: Fri Apr 21 2023(Updated: )
The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Orion Platform | <2023.2 |
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SolarWinds vulnerability is CVE-2022-36963.
The severity of CVE-2022-36963 is high with a severity value of 7.2.
The affected software by CVE-2022-36963 is the SolarWinds Orion Platform up to version 2023.2.
A remote adversary with a valid SolarWinds Platform admin account can exploit CVE-2022-36963 to execute arbitrary commands.
You can find more information about CVE-2022-36963 in the SolarWinds platform release notes and the SolarWinds security advisories.