← Back

CVE-2022-36966

nvd nist
Published: Oct 20, 2022Modified: May 7, 2025

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

Affected (9)

1 product
Orion Platform
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Solarwinds
Before 2020.2.6
Version 2020.2.6
Version 2020.2.6 hotfix1
Version 2020.2.6 hotfix2
Version 2020.2.6 hotfix3
Version 2020.2.6 hotfix4
Version 2020.2.6 hotfix5
Version 2022.2
Version 2022.3

Timeline

No history available yet.