Unrated severityNVD Advisory· Published Nov 29, 2022· Updated Apr 25, 2025
SolarWinds Platform Deserialization of Untrusted Data
CVE-2022-36964
Description
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.
Affected products
2- Range: 2022.3 and prior versions
- SolarWinds/Orion Platformv5Range: 2020.2.6 HF5 and prior versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.