Sensitive Information Disclosure Vulnerability
CVE-2022-38112
7.5HIGH
Key Information:
- Vendor
- Solarwinds
- Vendor
- CVE Published:
- 20 January 2023
Summary
In versions of SolarWinds Database Performance Analyzer (DPA) 2022.4 and earlier, there exists a vulnerability where generated heap memory dumps can expose sensitive information in cleartext format. This exposure could lead to unauthorized access to critical data, thus posing significant risks to the integrity and confidentiality of stored information. Organizations utilizing affected versions are strongly urged to upgrade to later releases and implement appropriate security measures to mitigate potential data breaches.
Affected Version(s)
Database Performance Analyzer (DPA) SolarWinds <= 2022.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved