Show plain JSON{"id": "CVE-2022-36964", "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "psirt@solarwinds.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}]}, "published": "2022-11-29T21:15:10.837", "references": [{"url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm", "tags": ["Release Notes", "Vendor Advisory"], "source": "psirt@solarwinds.com"}, {"url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36964", "tags": ["Vendor Advisory"], "source": "psirt@solarwinds.com"}, {"url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm", "tags": ["Release Notes", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36964", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "psirt@solarwinds.com", "description": [{"lang": "en", "value": "CWE-502"}]}, {"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-502"}]}], "descriptions": [{"lang": "en", "value": "SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands."}, {"lang": "es", "value": "La plataforma SolarWinds era susceptible a la deserializaci\u00f3n de datos no confiables. Esta vulnerabilidad permite que un adversario remoto con acceso v\u00e1lido a SolarWinds Web Console ejecute comandos arbitrarios."}], "lastModified": "2024-11-21T07:14:10.137", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01CD6BD2-A53E-4AB1-A08C-00540EC437E8", "versionEndExcluding": "2020.2.6"}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD239861-0422-45EE-9A3B-EED4F87F38F7"}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D577F745-35B0-44D8-A457-FD00C4FD4F76"}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "884E1621-E848-4769-BEF6-95A87F52A538"}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A60806A-14DE-4E9D-A55E-6DA128EF7661"}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E4171F0-1467-431C-A20C-6812045F9992"}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8F73D48-6F19-44D9-9F3E-B6AEB78946B8"}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2022.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A6214D0-6FDD-40F8-9955-CF3D616CB9A3"}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2022.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "077EB1C9-5CE5-48D8-9841-D11A2FB41098"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@solarwinds.com"}