Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Asim Liaquat

#47245of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2022-23712
5.4
2022-08-16
Solarwinds · Solarwinds Platform · CVE-2022-36966
**Name of the Vulnerable Software and Affected Versions** SolarWinds Platform versions 2022.3 and previous **Description** The issue is related to insufficient control on a URL parameter, causing an insecure direct object reference (IDOR) vulnerability. This allowed users with Node Management rights to view and edit all nodes. **Recommendations** For SolarWinds Platform versions 2022.3 and previous, update to a version that includes a fix for the insecure direct object reference vulnerability. As a temporary workaround, consider restricting Node Management rights to minimize the risk of exploitation.