High severity7.2NVD Advisory· Published Oct 20, 2022· Updated Jun 17, 2026
CVE-2022-38108
CVE-2022-38108
Description
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*range: <2020.2.6
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix3:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix4:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix5:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2022.2:*:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2022.3:*:*:*:*:*:*:*
- (no CPE)range: unspecified
(expand)+ 1 more
- (no CPE)
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
4- www.solarwinds.com/trust-center/security-advisories/CVE-2022-38108nvdVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-CAN-17531nvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/171567/SolarWinds-Information-Service-SWIS-Remote-Command-Execution.htmlnvd
- packetstorm.news/files/id/171567nvd
News mentions
0No linked articles in our index yet.