SolarWinds Platform是美国SolarWinds公司的一个统一监控、可观察性和服务管理平台。 SolarWinds Platform存在代码问题漏洞,该漏洞源于其易受不可信数据反序列化的影响导致能够访问SolarWinds Web控制台的远程攻击者执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SolarWinds | SolarWinds Platform | unspecified ~ 2022.3 and prior versions | - |
|
| SolarWinds | Orion Platform | unspecified ~ 2020.2.6 HF5 and prior versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-38108 | 7.2 HIGH | SolarWinds Platform Deserialization of Untrusted Data |
| CVE-2022-36957 | 7.2 HIGH | SolarWinds Platform Deserialization of Untrusted Data |
| CVE-2022-36966 | 5.4 MEDIUM | Insecure Direct Object Reference Vulnerability: Orion Platform 2020.2.6 |
No comments yet