VYPR
Medium severity5.4NVD Advisory· Published Oct 20, 2022· Updated Jun 17, 2026

CVE-2022-36966

CVE-2022-36966

Description

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • SolarWinds/Solarwinds Platformllm-fuzzy2 versions
    <=2022.3+ 1 more
    • (no CPE)range: <=2022.3
    • (no CPE)range: 2022.3 and previous
  • cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*range: <2020.2.6
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix3:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix4:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix5:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2022.2:*:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2022.3:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.