SolarWinds Security Updates 16 February 2023

SolarWinds has released security updates to fix multiple vulnerabilities in SolarWinds Platform and Server & Application Monitor.

The severity of the addressed vulnerabilities could allow the attacker with privileges to execute arbitrary commands on the affected product.

Sample of the addressed vulnerabilities:

1. SolarWinds Platform Deserialization of Untrusted Data Vulnerability (CVE-2023-23836):

• CVSS: 8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: Low

• User Interaction: None

• Consequences: Gain Access

2. SolarWinds Platform Directory Traversal (CVE-2022-47506):

• CVSS:8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: Low

• User Interaction: None

• Consequences: Gain Access

Vulnerabilities
  • CVE-2023-23836
  • CVE-2022-38111
  • CVE-2022-47503
  • CVE-2022-47504
  • CVE-2022-47506
  • CVE-2022-47507
  • CVE-2022-47508
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Advisory

References