CVE-2022-36966
Estado: ModificadaMedia (5.4)—
Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.45%
- Percentil entre todas las CVEs puntuadas: 37
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-639
- CWE-639
Referencias
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36966
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36966
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-36966",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-36966",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-07T20:49:47.424331Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@solarwinds.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@solarwinds.com",
"affectedData": [
{
"vendor": "SolarWinds",
"product": "SolarWinds Platform",
"versions": [
{
"status": "affected",
"version": "2022.3 and previous",
"lessThan": "2022.3",
"versionType": "custom"
}
],
"platforms": [
"Windows"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2022-10-20T21:15:10.050",
"references": [
{
"url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "psirt@solarwinds.com"
},
{
"url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36966",
"tags": [
"Vendor Advisory"
],
"source": "psirt@solarwinds.com"
},
{
"url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-4_release_notes.htm",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36966",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous."
},
{
"lang": "es",
"value": "Los usuarios con derechos de administración de nodos podían ver y editar todos los nodos debido a un control insuficiente del parámetro URL que causaba una vulnerabilidad de referencia directa a objetos insegura (IDOR) en SolarWinds Platform 2022.3 y anteriores"
}
],
"lastModified": "2026-06-17T04:54:22.080",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01CD6BD2-A53E-4AB1-A08C-00540EC437E8",
"versionEndExcluding": "2020.2.6"
},
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD239861-0422-45EE-9A3B-EED4F87F38F7"
},
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D577F745-35B0-44D8-A457-FD00C4FD4F76"
},
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "884E1621-E848-4769-BEF6-95A87F52A538"
},
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A60806A-14DE-4E9D-A55E-6DA128EF7661"
},
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E4171F0-1467-431C-A20C-6812045F9992"
},
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8F73D48-6F19-44D9-9F3E-B6AEB78946B8"
},
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:2022.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A6214D0-6FDD-40F8-9955-CF3D616CB9A3"
},
{
"criteria": "cpe:2.3:a:solarwinds:orion_platform:2022.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "077EB1C9-5CE5-48D8-9841-D11A2FB41098"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@solarwinds.com"
}