← Back to browse · API

CVE-2022-36964

Severity
HIGH
CVSS
8.8
EPSS
0.16813
Risk score
41.08
CISA KEV
No
PoC
No
Published
2022-11-29
Modified
2025-04-25
First seen
2026-08-07
Aliases
EUVD-2022-39621, GHSA-X499-M338-RW37
Products
SolarWinds:Orion Platform 2020.2.6 HF5 and prior versions ≤2020.2.6 HF5, SolarWinds:SolarWinds Platform 2022.3 and prior versions ≤2022.3
Sources
euvd EUVD-2022-39621

Description

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

References