Lucene search

K
cveSolarWindsCVE-2022-36966
HistoryOct 20, 2022 - 9:15 p.m.

CVE-2022-36966

2022-10-2021:15:10
CWE-639
SolarWinds
web.nvd.nist.gov
36
9
cve-2022-36966
node management
idor
solarwinds platform
security vulnerability

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

22.7%

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

Affected configurations

Nvd
Node
solarwindsorion_platformRange<2020.2.6
OR
solarwindsorion_platformMatch2020.2.6-
OR
solarwindsorion_platformMatch2020.2.6hotfix1
OR
solarwindsorion_platformMatch2020.2.6hotfix2
OR
solarwindsorion_platformMatch2020.2.6hotfix3
OR
solarwindsorion_platformMatch2020.2.6hotfix4
OR
solarwindsorion_platformMatch2020.2.6hotfix5
OR
solarwindsorion_platformMatch2022.2
OR
solarwindsorion_platformMatch2022.3
VendorProductVersionCPE
solarwindsorion_platform*cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*
solarwindsorion_platform2020.2.6cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*
solarwindsorion_platform2020.2.6cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*
solarwindsorion_platform2020.2.6cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*
solarwindsorion_platform2020.2.6cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix3:*:*:*:*:*:*
solarwindsorion_platform2020.2.6cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix4:*:*:*:*:*:*
solarwindsorion_platform2020.2.6cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix5:*:*:*:*:*:*
solarwindsorion_platform2022.2cpe:2.3:a:solarwinds:orion_platform:2022.2:*:*:*:*:*:*:*
solarwindsorion_platform2022.3cpe:2.3:a:solarwinds:orion_platform:2022.3:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "SolarWinds Platform",
    "vendor": "SolarWinds",
    "versions": [
      {
        "lessThan": "2022.3",
        "status": "affected",
        "version": "2022.3 and previous",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for CVE-2022-36966