CVE-2022-36963: SolarWinds Platform Deserialization of Untrusted Data Vulnerability
Published Apr 21, 2023
·Updated
The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.
Affected Software
1 affected component
SolarWinds Orion Platform<2023.2
Remediation
Information
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.2
Event History
Apr 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SolarWinds vulnerability?
The vulnerability ID for this SolarWinds vulnerability is CVE-2022-36963.
2
What is the severity of CVE-2022-36963?
The severity of CVE-2022-36963 is high with a severity value of 7.2.
3
What is the affected software by CVE-2022-36963?
The affected software by CVE-2022-36963 is the SolarWinds Orion Platform up to version 2023.2.
4
How can a remote adversary exploit CVE-2022-36963?
A remote adversary with a valid SolarWinds Platform admin account can exploit CVE-2022-36963 to execute arbitrary commands.
5
Where can I find more information about CVE-2022-36963?
You can find more information about CVE-2022-36963 in the SolarWinds platform release notes and the SolarWinds security advisories.