SolarWinds Platform Incorrect Input Neutralization Vulnerability (CVE-2022-47509)

Summary

The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.

Affected Products

  • SolarWinds Platform 2023.1 and earlier

Fixed Software Release

  • SolarWinds Platform 2023.2

Acknowledgments

  • Juampa Rodriguez (@UnD3sc0n0c1d0)

Workarounds

SolarWinds recommends customers upgrade to SolarWinds Platform version 2023.2 as soon as it becomes available. The expected release is by the end of April 2023. SolarWinds also recommends customers to follow the guidance provided in the SolarWinds Secure Configuration Guide. Ensure only authorized users can access the SolarWinds Platform. Special attention should be given to the following points from the documentation:

Advisory Details
Severity
Medium
Advisory ID
First Published
04/18/2023
Last Updated
04/18/2023
Fixed Version

SolarWinds Platform 2023.2

CVSS Score
Download PDF
Send an Email