CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AI Score
Confidence
High
EPSS
Percentile
33.5%
Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).
Vendor | Product | Version | CPE |
---|---|---|---|
solarwinds | solarwinds_platform | * | cpe:2.3:a:solarwinds:solarwinds_platform:*:*:*:*:*:*:*:* |
[
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "Orion Platform",
"vendor": "SolarWinds",
"versions": [
{
"lessThan": "2022.3.0",
"status": "affected",
"version": "2020.2.6 and previous versions",
"versionType": "custom"
}
]
}
]
documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-3_release_notes.htm#:~:text=Release%20date%3A%20May%2024%2C%202022%20These%20release%20notes%2Cissues.%20New%20features%20and%20improvements%20in%20SolarWinds%20Platform
www.solarwinds.com/trust-center/security-advisories/CVE-2022-36965
More