ZeroHour

CVE-2022-36966

CVSS 3.1
5.4 medium
EPSS
<1%p36
Published
()
Modified
Description

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

Vendors
solarwinds
Products
orion platform
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.