First published: Fri Jan 20 2023(Updated: )
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Database Performance Analyzer | <=2022.4 |
SolarWinds has released a Service Release to address this vulnerability in Database Performance Analyzer (DPA) 2023.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38112 is a vulnerability found in DPA 2022.4 and older releases, where generated heap memory dumps contain sensitive information in cleartext.
The severity of CVE-2022-38112 is high, with a severity value of 7.5.
CVE-2022-38112 affects Solarwinds Database Performance Analyzer versions up to and including 2022.4.
To fix CVE-2022-38112, make sure to upgrade to a version of DPA that is newer than 2022.4.
You can find more information about CVE-2022-38112 in the release notes for DPA 2023.1 and the Solarwinds Trust Center security advisories.