SolarWinds Platform Deserialization of Untrusted Data 

(CVE-2022-38108)

Security Advisory Summary

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

Affected Products

  • SolarWinds Platform 2022.3 and earlier
  • Orion Platform 2020.2.6 HF5 and earlier

Fixed Software Release

  • SolarWinds Platform 2022.4 RC1

Acknowledgments

  • Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative

Workarounds

SolarWinds recommends customers upgrade to SolarWinds Platform version 2022.4 RC1 as soon as it becomes available. The expected RC release is at the end of October. SolarWinds also recommends that customers follow the guidance provided in the SolarWinds Secure Configuration Guide. Ensure only authorized users can access the SolarWinds Platform. Special attention should be given to the following points from documentation:

Advisory Details

Severity

7.2 High

Advisory ID

First Published

10/19/2022

Fixed Version

SolarWinds Platform 2022.4 RC1