Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.
History

Wed, 07 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
Description Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous. Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.

cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published: 2022-10-20T20:05:35.645Z

Updated: 2025-05-07T20:49:50.846Z

Reserved: 2022-07-27T00:00:00.000Z

Link: CVE-2022-36966

cve-icon Vulnrichment

Updated: 2024-08-03T10:21:32.223Z

cve-icon NVD

Status : Modified

Published: 2022-10-20T21:15:10.050

Modified: 2025-05-07T21:15:55.467

Link: CVE-2022-36966

cve-icon Redhat

No data.