#VU75207 OS Command Injection in Orion Platform - CVE-2022-36963
Published: April 18, 2023 / Updated: April 25, 2023
Orion Platform
SolarWinds
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the ExecuteExternalProgram method. A remote authenticated user with SolarWinds Platform admin account can pass specially crafted data to the application and execute arbitrary OS commands on the target system.