CVE-2022-38112: Sensitive Information Disclosure Vulnerability
Published Jan 20, 2023
·Updated
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
Affected Software
1 affected component
SolarWinds Database Performance Analyzer<=2022.4
Remediation
Information
SolarWinds has released a Service Release to address this vulnerability in Database Performance Analyzer (DPA) 2023.1
Event History
Jan 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38112?
CVE-2022-38112 is a vulnerability found in DPA 2022.4 and older releases, where generated heap memory dumps contain sensitive information in cleartext.
2
What is the severity of CVE-2022-38112?
The severity of CVE-2022-38112 is high, with a severity value of 7.5.
3
How does CVE-2022-38112 affect Solarwinds Database Performance Analyzer?
CVE-2022-38112 affects Solarwinds Database Performance Analyzer versions up to and including 2022.4.
4
How can I fix CVE-2022-38112?
To fix CVE-2022-38112, make sure to upgrade to a version of DPA that is newer than 2022.4.
5
Where can I find more information about CVE-2022-38112?
You can find more information about CVE-2022-38112 in the release notes for DPA 2023.1 and the Solarwinds Trust Center security advisories.