Solarwinds Platform
by SolarWinds
CVEs (48)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36962 | Hig | 0.48 | 7.2 | 0.09 | Nov 29, 2022 | SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands. | ||
| CVE-2022-36957 | Hig | 0.48 | 7.2 | 0.12 | Oct 20, 2022 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2023-33225 | Hig | 0.47 | 7.2 | 0.03 | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges. | ||
| CVE-2023-33224 | Hig | 0.47 | 7.2 | 0.03 | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges. | ||
| CVE-2023-23844 | Hig | 0.47 | 7.2 | 0.03 | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges. | ||
| CVE-2023-23843 | Hig | 0.47 | 7.2 | 0.03 | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2022-36963 | Hig | 0.47 | 7.2 | 0.08 | Apr 21, 2023 | The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands. | ||
| CVE-2022-47507 | Hig | 0.47 | 7.2 | 0.07 | Feb 15, 2023 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2024-45717 | Hig | 0.46 | 7.0 | 0.00 | Dec 4, 2024 | The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication and requires user interaction. | ||
| CVE-2024-45715 | Hig | 0.46 | 7.1 | 0.00 | Oct 16, 2024 | The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements. | ||
| CVE-2024-29004 | Hig | 0.46 | 7.1 | 0.00 | Jun 4, 2024 | The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability. | ||
| CVE-2024-28999 | Med | 0.46 | 6.4 | 0.14 | Jun 4, 2024 | The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. | ||
| CVE-2024-28076 | Hig | 0.46 | 7.0 | 0.00 | Apr 18, 2024 | The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format | ||
| CVE-2023-23845 | Med | 0.45 | 6.8 | 0.05 | Sep 13, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges. | ||
| CVE-2023-23840 | Med | 0.45 | 6.8 | 0.05 | Sep 13, 2023 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges. | ||
| CVE-2024-52612 | Med | 0.44 | 6.8 | 0.01 | Feb 11, 2025 | SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. This vulnerability requires authentication by a high- privileged account to be exploitable. | ||
| CVE-2023-23839 | Med | 0.42 | 6.5 | 0.01 | Apr 25, 2023 | The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information. | ||
| CVE-2022-47509 | Med | 0.40 | 6.1 | 0.01 | Apr 21, 2023 | The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML. | ||
| CVE-2022-36965 | Med | 0.40 | 6.1 | 0.01 | Sep 30, 2022 | Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0). | ||
| CVE-2022-47512 | Med | 0.36 | 5.5 | 0.00 | Dec 19, 2022 | Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected |
- risk 0.48cvss 7.2epss 0.09
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands.
- risk 0.48cvss 7.2epss 0.12
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.47cvss 7.2epss 0.03
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
- risk 0.47cvss 7.2epss 0.03
The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
- risk 0.47cvss 7.2epss 0.03
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.
- risk 0.47cvss 7.2epss 0.03
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.47cvss 7.2epss 0.08
The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.
- risk 0.47cvss 7.2epss 0.07
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.46cvss 7.0epss 0.00
The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication and requires user interaction.
- risk 0.46cvss 7.1epss 0.00
The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.
- risk 0.46cvss 7.1epss 0.00
The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.
- risk 0.46cvss 6.4epss 0.14
The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.
- risk 0.46cvss 7.0epss 0.00
The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format
- risk 0.45cvss 6.8epss 0.05
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
- risk 0.45cvss 6.8epss 0.05
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
- risk 0.44cvss 6.8epss 0.01
SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. This vulnerability requires authentication by a high- privileged account to be exploitable.
- risk 0.42cvss 6.5epss 0.01
The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information.
- risk 0.40cvss 6.1epss 0.01
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.
- risk 0.40cvss 6.1epss 0.01
Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).
- risk 0.36cvss 5.5epss 0.00
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected
Page 2 of 3