Back

HIGH

SolarWinds Platform Deserialization of Untrusted Data Vulnerability

Published Feb 15, 2023

Description

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

Affected products

Remediation

Vendor solution

All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.1

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SolarWinds
Published Feb 15, 2023
Updated Mar 18, 2025
Reserved Dec 15, 2022
CISA Vulnrichment
Updated Mar 18, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner SolarWinds
Published Feb 15, 2023
Updated Mar 18, 2025
Exploited since n/a
EUVD-2022-50264