Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*", "matchCriteriaId": "01CD6BD2-A53E-4AB1-A08C-00540EC437E8", "versionEndExcluding": "2020.2.6", "vulnerable": true}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*", "matchCriteriaId": "AD239861-0422-45EE-9A3B-EED4F87F38F7", "vulnerable": true}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*", "matchCriteriaId": "D577F745-35B0-44D8-A457-FD00C4FD4F76", "vulnerable": true}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*", "matchCriteriaId": "884E1621-E848-4769-BEF6-95A87F52A538", "vulnerable": true}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix3:*:*:*:*:*:*", "matchCriteriaId": "4A60806A-14DE-4E9D-A55E-6DA128EF7661", "vulnerable": true}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix4:*:*:*:*:*:*", "matchCriteriaId": "3E4171F0-1467-431C-A20C-6812045F9992", "vulnerable": true}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix5:*:*:*:*:*:*", "matchCriteriaId": "D8F73D48-6F19-44D9-9F3E-B6AEB78946B8", "vulnerable": true}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2022.2:*:*:*:*:*:*:*", "matchCriteriaId": "0A6214D0-6FDD-40F8-9955-CF3D616CB9A3", "vulnerable": true}, {"criteria": "cpe:2.3:a:solarwinds:orion_platform:2022.3:*:*:*:*:*:*:*", "matchCriteriaId": "077EB1C9-5CE5-48D8-9841-D11A2FB41098", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands."}, {"lang": "es", "value": "La plataforma SolarWinds era susceptible a la deserializaci\u00f3n de datos no confiables. Esta vulnerabilidad permite que un adversario remoto con acceso v\u00e1lido a SolarWinds Web Console ejecute comandos arbitrarios."}], "id": "CVE-2022-36964", "lastModified": "2024-11-21T07:14:10.137", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "psirt@solarwinds.com", "type": "Secondary"}, {"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "exploitabilityScore": 2.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2022-11-29T21:15:10.837", "references": [{"source": "psirt@solarwinds.com", "tags": ["Release Notes", "Vendor Advisory"], "url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm"}, {"source": "psirt@solarwinds.com", "tags": ["Vendor Advisory"], "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36964"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Release Notes", "Vendor Advisory"], "url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36964"}], "sourceIdentifier": "psirt@solarwinds.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-502"}], "source": "psirt@solarwinds.com", "type": "Secondary"}, {"description": [{"lang": "en", "value": "CWE-502"}], "source": "nvd@nist.gov", "type": "Primary"}]}