First published: Wed Jul 26 2023(Updated: )
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
Solarwinds Solarwinds Platform | <=2023.2.1 | |
<=2023.2.1 |
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3622 is an Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource.
The SolarWinds Platform version 2023.2.1 and prior versions are affected by CVE-2023-3622.
CVE-2023-3622 has a severity rating of medium with a CVSS score of 4.3.
An underprivileged user can exploit CVE-2023-3622 to read arbitrary resources.
You can find more information about CVE-2023-3622 in the SolarWinds Platform 2023.3 release notes and the SolarWinds Trust Center security advisories.