High
CVE-2022-36964 CVSS:8.8
The vulnerability exists due to insecure input validation when processing serialized data within the DeserializeFromStrippedXml() function in SolarWinds Web Console. A remote user can pass specially crafted data to the application and execute arbitrary code on the target system.
CVE-2022-36962 CVSS:7.2
The vulnerability exists due to improper input validation within the GetPdf function. A remote privileged user with complete control over the SolarWinds database can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
CVE-2022-36960 CVSS:
The vulnerability exists due to insufficient validation of user-supplied input within the CheckWhetherNonAdminAttemptsToModifyBlacklistedRecords function in SolarWinds Web Console. A remote user can send specially crafted input to the application and execute arbitrary code on the system.
SolarWinds
Refer to SolarWinds Secure Configuration Guide for patch, upgrade or suggested workaround information.
SolarWinds Secure Configuration Guide