Vulnerability Details CVE-2022-36957
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.1%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2022-36957
-
cpe:2.3:a:solarwinds:orion_platform:2016.1
-
cpe:2.3:a:solarwinds:orion_platform:2016.2
-
cpe:2.3:a:solarwinds:orion_platform:2017.1
-
cpe:2.3:a:solarwinds:orion_platform:2017.3
-
cpe:2.3:a:solarwinds:orion_platform:2018.2
-
cpe:2.3:a:solarwinds:orion_platform:2018.4
-
cpe:2.3:a:solarwinds:orion_platform:2019.2
-
cpe:2.3:a:solarwinds:orion_platform:2019.4
-
cpe:2.3:a:solarwinds:orion_platform:2019.4.2
-
cpe:2.3:a:solarwinds:orion_platform:2020.2
-
cpe:2.3:a:solarwinds:orion_platform:2020.2.1
-
cpe:2.3:a:solarwinds:orion_platform:2020.2.4
-
cpe:2.3:a:solarwinds:orion_platform:2020.2.5
-
cpe:2.3:a:solarwinds:orion_platform:2020.2.6
-
cpe:2.3:a:solarwinds:orion_platform:2022.2
-
cpe:2.3:a:solarwinds:orion_platform:2022.3