PT-2023-2270 · Solarwinds · Solarwinds Server/Application Monitor

CVE-2022-47508

·

Publicado

2023-02-15

·

Atualizado

2023-02-24

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Solarwinds Server & Application Monitor (affected versions not specified)
Description The issue is related to weaknesses in the authentication procedure, allowing a remote attacker to bypass authentication and access confidential information using specially crafted NTLM protocol messages. Customers who configured polling via Kerberos did not expect NTLM traffic, but querying data via IP address prevented the use of Kerberos.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02031
CVE-2022-47508

Produtos afetados

Solarwinds Server/Application Monitor