// For flags

CVE-2022-36966

Insecure Direct Object Reference Vulnerability: Orion Platform 2020.2.6

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

Los usuarios con derechos de administración de nodos podían ver y editar todos los nodos debido a un control insuficiente del parámetro URL que causaba una vulnerabilidad de referencia directa a objetos insegura (IDOR) en SolarWinds Platform 2022.3 y anteriores

*Credits: Asim Liaquat
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-07-27 CVE Reserved
  • 2022-10-20 CVE Published
  • 2024-05-11 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
< 2020.2.6
Search vendor "Solarwinds" for product "Orion Platform" and version " < 2020.2.6"
-
Affected
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
2020.2.6
Search vendor "Solarwinds" for product "Orion Platform" and version "2020.2.6"
-
Affected
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
2020.2.6
Search vendor "Solarwinds" for product "Orion Platform" and version "2020.2.6"
hotfix1
Affected
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
2020.2.6
Search vendor "Solarwinds" for product "Orion Platform" and version "2020.2.6"
hotfix2
Affected
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
2020.2.6
Search vendor "Solarwinds" for product "Orion Platform" and version "2020.2.6"
hotfix3
Affected
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
2020.2.6
Search vendor "Solarwinds" for product "Orion Platform" and version "2020.2.6"
hotfix4
Affected
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
2020.2.6
Search vendor "Solarwinds" for product "Orion Platform" and version "2020.2.6"
hotfix5
Affected
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
2022.2
Search vendor "Solarwinds" for product "Orion Platform" and version "2022.2"
-
Affected
Solarwinds
Search vendor "Solarwinds"
Orion Platform
Search vendor "Solarwinds" for product "Orion Platform"
2022.3
Search vendor "Solarwinds" for product "Orion Platform" and version "2022.3"
-
Affected