Back

HIGH

SolarWinds Platform Deserialization of Untrusted Data Vulnerability

Published Feb 15, 2023

Description

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

Affected products

Remediation

Vendor solution

All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.1

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner SolarWinds
Published Feb 15, 2023
Updated Mar 18, 2025
Reserved Dec 15, 2022

CISA Vulnrichment

Updated Mar 18, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner SolarWinds
Published Feb 15, 2023
Updated Mar 18, 2025

GitHub

No data