PT-2023-2038 · Solarwinds · Solarwinds Platform

Chudypb

+1

·

Published

2023-02-15

·

Updated

2023-10-27

·

CVE-2022-47504

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SolarWinds Platform (affected versions not specified)
Description The issue is related to the Deserialization of Untrusted Data, allowing a remote adversary with admin-level account access to the SolarWinds Web Console to execute arbitrary commands. This can be exploited by an attacker to gain unauthorized access and control over the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2023-01755
CVE-2022-47504
ZDI-23-166

Affected Products

Solarwinds Platform