#VU72303 Path traversal in Orion Platform - CVE-2022-47506
Published: February 15, 2023 / Updated: February 25, 2023
Orion Platform
SolarWinds
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the sshd_SftpRename function. A remote user can send a specially crafted HTTP request and update the default configuration, enabling the execution of arbitrary commands.
Successful exploitation of the vulnerability may allow remote code execution.