SolarWinds Platform是美国SolarWinds公司的一个统一监控、可观察性和服务管理平台。 SolarWinds Platform 2022.4.1版本存在安全漏洞,该漏洞源于容易受到反序列化不可信数据的影响,攻击者利用该漏洞可以访问 SolarWinds Web Console 以执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SolarWinds | SolarWinds Platform | 2022.4.1 and prior versions ~ 2022.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-47506 | 7.8 HIGH | SolarWinds Platform Directory Traversal Vulnerability |
| CVE-2022-47508 | 7.5 HIGH | Disable NTLM: SAM 2022.4 |
| CVE-2022-38111 | 7.2 HIGH | SolarWinds Platform Deserialization of Untrusted Data Vulnerability |
| CVE-2022-47503 | 7.2 HIGH | SolarWinds Platform Deserialization of Untrusted Data Vulnerability |
| CVE-2022-47504 | 7.2 HIGH | SolarWinds Platform Deserialization of Untrusted Data Vulnerability |
| CVE-2022-47507 | 7.2 HIGH | SolarWinds Platform Deserialization of Untrusted Data Vulnerability |
No comments yet