Aller au contenu

Fiche vulnérabilité

CVE-2022-36963 : faille élevée SolarWinds Platform Command Injection… (CVSS 7.2)

Description

The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
21 avr. 2023
Dernière mise à jour
5 févr. 2025

Produits concernés

  • SolarWinds Platform Command Injection Vulnerability SolarWinds Platform

Correctif et mesures

All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.2

Références

Rechercher une autre vulnérabilité dans la base CVE