QID 378098
Date Published: 2023-03-22
QID 378098: Solarwinds Platform Multiple Vulnerabilities
SolarWinds Platform is an IT performance monitoring platform.
Affected Products:
SolarWinds Platform 2022.4.1 and earlier
QID Detection Logic (Authenticated):
1. The QID extracts Solarwinds Orion Platform version from registry key "HKLM\SOFTWARE\SolarWinds\Orion\Core or HKLM\SOFTWARE\Wow6432Node\SolarWinds\Orion\Core", value "InstallPath", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions
2. The QID extracts Solarwinds Orion Platform version from registry key "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall or HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall", value "InstallLocation", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions
An attacker could exploit these vulnerabilities to compromise confidentiality, integrity and availability.
Customers are advised to refer to SolarWinds Platform
- cve-2022-38111 -
www.solarwinds.com/trust-center/security-advisories/cve-2022-38111 - cve-2022-47503 -
www.solarwinds.com/trust-center/security-advisories/cve-2022-47503 - cve-2022-47504 -
www.solarwinds.com/trust-center/security-advisories/cve-2022-47504 - cve-2022-47506 -
www.solarwinds.com/trust-center/security-advisories/cve-2022-47506 - cve-2022-47507 -
www.solarwinds.com/trust-center/security-advisories/cve-2022-47507 - cve-2023-23836 -
www.solarwinds.com/trust-center/security-advisories/cve-2023-23836
CVEs related to QID 378098
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SolarWinds |
|