Sensitive Information Disclosure Vulnerability
CVE-2022-38112

7.5HIGH

Key Information:

Vendor
Solarwinds
Vendor
CVE Published:
20 January 2023

Summary

In versions of SolarWinds Database Performance Analyzer (DPA) 2022.4 and earlier, there exists a vulnerability where generated heap memory dumps can expose sensitive information in cleartext format. This exposure could lead to unauthorized access to critical data, thus posing significant risks to the integrity and confidentiality of stored information. Organizations utilizing affected versions are strongly urged to upgrade to later releases and implement appropriate security measures to mitigate potential data breaches.

Affected Version(s)

Database Performance Analyzer (DPA) SolarWinds <= 2022.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.