CVE-2022-38110: Reflected Cross-Site Scripting Vulnerability
Published Jan 20, 2023
·Updated
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
Affected Software
1 affected component
SolarWinds Database Performance Analyzer<=2022.4
Remediation
Information
SolarWinds has released a Service Release to address this vulnerability in Database Performance Analyzer (DPA) 2023.1
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38110?
CVE-2022-38110 is a vulnerability in the SolarWinds Database Performance Analyzer (DPA) 2022.4 and older releases.
2
How severe is CVE-2022-38110?
CVE-2022-38110 has a severity rating of 5.4, which is considered medium.
3
What is the affected software by CVE-2022-38110?
The affected software is SolarWinds Database Performance Analyzer (DPA) versions up to and including 2022.4.
4
What is the CWE ID of CVE-2022-38110?
The CWE ID of CVE-2022-38110 is 79.
5
How can I fix CVE-2022-38110?
To fix CVE-2022-38110, it is recommended to upgrade to a newer release of SolarWinds Database Performance Analyzer (DPA) that is not affected by the vulnerability.