QID 378484

Date Published: 2023-05-29

QID 378484: SolarWinds Platform Multiple Vulnerabilities

SolarWinds Platform is an IT performance monitoring platform.

Affected Products:
SolarWinds Platform 2016.1 prior to 2023.2

QID Detection Logic (Authenticated):
1. The QID extracts Solarwinds Orion Platform version from registry key "HKLM\SOFTWARE\SolarWinds\Orion\Core or HKLM\SOFTWARE\Wow6432Node\SolarWinds\Orion\Core", value "InstallPath", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions
2. The QID extracts Solarwinds Orion Platform version from registry key "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall or HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall", value "InstallLocation", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions

Successful exploitation of this vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cve-2022-47509
    cve-2022-47505
    cve-2022-36963

    CVEs related to QID 378484

    Software Advisories
    Advisory ID Software Component Link
    cve-2022-36963 URL Logo www.solarwinds.com/trust-center/security-advisories/cve-2022-36963
    cve-2022-47505 URL Logo www.solarwinds.com/trust-center/security-advisories/cve-2022-47505
    cve-2022-47509 URL Logo www.solarwinds.com/trust-center/security-advisories/cve-2022-47509