CVE-2022-36966: Insecure Direct Object Reference Vulnerability: Orion Platform 2020.2.6
Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36966?
CVE-2022-36966 is an insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous, allowing users with Node Management rights to view and edit all nodes due to insufficient control on URL parameter.
What is the severity of CVE-2022-36966?
The severity of CVE-2022-36966 is medium with a CVSS score of 5.4.
What software versions are affected by CVE-2022-36966?
SolarWinds Orion Platform versions 2020.2.6, 2020.2.6-hotfix1, 2020.2.6-hotfix2, 2020.2.6-hotfix3, 2020.2.6-hotfix4, 2020.2.6-hotfix5, 2022.2, and 2022.3 are affected by CVE-2022-36966.
How can I fix CVE-2022-36966?
To fix CVE-2022-36966, update SolarWinds Orion Platform to version 2022.4 or later.
Where can I find more information about CVE-2022-36966?
You can find more information about CVE-2022-36966 on the SolarWinds documentation website and the SolarWinds Trust Center security advisories.