CVE-2022-47509: SolarWinds Platform Incorrect Input Neutralization Vulnerability
Published Apr 21, 2023
·Updated
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.
Affected Software
1 affected component
SolarWinds Orion Platform<2023.2
Remediation
Information
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.2
Event History
Apr 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-47509?
CVE-2022-47509 is the vulnerability that allows a remote adversary to inject HTML into the SolarWinds Platform by appending URL parameters.
2
How severe is CVE-2022-47509?
CVE-2022-47509 has a severity rating of 6.1 (medium).
3
What software is affected by CVE-2022-47509?
The SolarWinds Orion Platform up to version 2023.2 is affected by CVE-2022-47509.
4
How can I fix CVE-2022-47509?
To fix CVE-2022-47509, update your SolarWinds Orion Platform to version 2023.2 or newer.
5
Where can I find more information about CVE-2022-47509?
You can find more information about CVE-2022-47509 in the SolarWinds Platform 2023.2 release notes and the SolarWinds Trust Center security advisories.