← Back to browse · API

CVE-2022-38108

Severity
HIGH
CVSS
7.2
EPSS
0.67959
Risk score
52.59
CISA KEV
No
PoC
No
Published
2022-10-20
Modified
2025-05-08
First seen
2026-08-07
Aliases
EUVD-2022-40710, GHSA-23MM-62VV-WV83
Products
SolarWinds:Orion Platform unspecified ≤2020.2.6 HF5 and prior versions, SolarWinds:SolarWinds Platform unspecified ≤2022.3 and prior versions
Sources
euvd EUVD-2022-40710

Description

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

References