Skip to main content

Vendor/product archive

solarwinds / orion_platform CVEs

Beta · best-effort

49 CVEs tagged to solarwinds / orion_platform5 Critical, 26 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2023-23845

Published Sep 13, 2023

The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23840

Published Sep 13, 2023

The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47509

Published Apr 21, 2023

The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-47505

Published Apr 21, 2023

The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate l…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-36963

Published Apr 21, 2023

The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to exec…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-23836

Published Feb 15, 2023

SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acco…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-47507

Published Feb 15, 2023

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-47506

Published Feb 15, 2023

SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default con…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-47504

Published Feb 15, 2023

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-47503

Published Feb 15, 2023

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-38111

Published Feb 15, 2023

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-36964

Published Nov 29, 2022

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36962

Published Nov 29, 2022

SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary comm…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36960

Published Nov 29, 2022

SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privile…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38108

Published Oct 20, 2022

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36966

Published Oct 20, 2022

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36958

Published Oct 20, 2022

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36957

Published Oct 20, 2022

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36961

Published Sep 30, 2022

A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35234

Published Dec 20, 2021

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal pass…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35218

Published Sep 1, 2021

Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager W…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35215

Published Sep 1, 2021

Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35238

Published Sep 1, 2021

User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 49 CVEsPage 1 of 2