CVE-2023-3622: Access Control Bypass Vulnerability in the SolarWinds Platform
Published Jul 26, 2023
·Updated
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource
Affected Software
1 affected component
SolarWinds SolarWinds Platform<=2023.2.1
Remediation
Information
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.3
Event History
Jul 26, 2023
CVE Published
02:45 PM
Data Sourced
02:45 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-3622?
CVE-2023-3622 is an Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource.
2
What software is affected by CVE-2023-3622?
The SolarWinds Platform version 2023.2.1 and prior versions are affected by CVE-2023-3622.
3
What is the severity of CVE-2023-3622?
CVE-2023-3622 has a severity rating of medium with a CVSS score of 4.3.
4
How can an underprivileged user exploit CVE-2023-3622?
An underprivileged user can exploit CVE-2023-3622 to read arbitrary resources.
5
Where can I find more information about CVE-2023-3622?
You can find more information about CVE-2023-3622 in the SolarWinds Platform 2023.3 release notes and the SolarWinds Trust Center security advisories.