SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Orion_platform | Solarwinds | * | 2020.2.6 (excluding) |
Orion_platform | Solarwinds | 2020.2.6 (including) | 2020.2.6 (including) |
Orion_platform | Solarwinds | 2020.2.6-hotfix1 (including) | 2020.2.6-hotfix1 (including) |
Orion_platform | Solarwinds | 2020.2.6-hotfix2 (including) | 2020.2.6-hotfix2 (including) |
Orion_platform | Solarwinds | 2020.2.6-hotfix3 (including) | 2020.2.6-hotfix3 (including) |
Orion_platform | Solarwinds | 2020.2.6-hotfix4 (including) | 2020.2.6-hotfix4 (including) |
Orion_platform | Solarwinds | 2020.2.6-hotfix5 (including) | 2020.2.6-hotfix5 (including) |
Orion_platform | Solarwinds | 2022.2 (including) | 2022.2 (including) |
Orion_platform | Solarwinds | 2022.3 (including) | 2022.3 (including) |