Vulnerabilities > Solarwinds > Orion Platform > 2022.3

DATE CVE VULNERABILITY TITLE RISK
2023-09-13 CVE-2023-23840 Incorrect Comparison vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability.
network
low complexity
solarwinds CWE-697
7.2
2023-09-13 CVE-2023-23845 Incorrect Comparison vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability.
network
low complexity
solarwinds CWE-697
7.2
2023-04-21 CVE-2022-36963 Code Injection vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Command Injection Vulnerability.
network
low complexity
solarwinds CWE-94
7.2
2023-04-21 CVE-2022-47505 Improper Privilege Management vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability.
local
low complexity
solarwinds CWE-269
7.8
2023-04-21 CVE-2022-47509 Cross-site Scripting vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability.
network
low complexity
solarwinds CWE-79
6.1
2022-11-29 CVE-2022-36960 Improper Input Validation vulnerability in Solarwinds Orion Platform
SolarWinds Platform was susceptible to Improper Input Validation.
network
low complexity
solarwinds CWE-20
8.8
2022-11-29 CVE-2022-36962 Command Injection vulnerability in Solarwinds Orion Platform
SolarWinds Platform was susceptible to Command Injection.
network
low complexity
solarwinds CWE-77
7.2
2022-11-29 CVE-2022-36964 Deserialization of Untrusted Data vulnerability in Solarwinds Orion Platform
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.
network
low complexity
solarwinds CWE-502
8.8
2022-10-20 CVE-2022-36957 Deserialization of Untrusted Data vulnerability in Solarwinds Orion Platform
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.
network
low complexity
solarwinds CWE-502
7.2
2022-10-20 CVE-2022-36958 Deserialization of Untrusted Data vulnerability in Solarwinds Orion Platform
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data.
network
low complexity
solarwinds CWE-502
8.8