CVE-2022-38114: Client-Side Desync Vulnerability
This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-38114?
CVE-2022-38114 is a vulnerability that occurs when a web server fails to correctly process the Content-Length of POST requests, leading to HTTP request smuggling or XSS.
What software is affected by CVE-2022-38114?
Solarwinds Security Event Manager versions up to and excluding 2022.4 are affected by CVE-2022-38114.
What is the severity of CVE-2022-38114?
CVE-2022-38114 has a severity value of 6.1, which is classified as medium.
How can I fix CVE-2022-38114?
To fix CVE-2022-38114, it is recommended to update Solarwinds Security Event Manager to version 2022.4 or later.
Where can I find more information about CVE-2022-38114?
More information about CVE-2022-38114 can be found in the release notes for Solarwinds Security Event Manager version 2022.4 and in the Solarwinds security advisories.