CVE-2022-36961

HIGH

SolarWinds Orion Platform < 2022.2.0 - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.

Scores

CVSS v3 8.8
EPSS 0.1177
EPSS Percentile 93.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
solarwinds/orion_platform < 2022.2.0
Published Sep 30, 2022
Tracked Since Feb 18, 2026