CVE-2022-38115

Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT
Configurations

Configuration 1 (hide)

cpe:2.3:a:solarwinds:security_event_manager:*:*:*:*:*:*:*:*

History

28 Nov 2022, 18:20

Type Values Removed Values Added
References (MISC) https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-38115 - (MISC) https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-38115 - Vendor Advisory
References (MISC) https://documentation.solarwinds.com/en/success_center/sem/content/release_notes/sem_2022-4_release_notes.htm - (MISC) https://documentation.solarwinds.com/en/success_center/sem/content/release_notes/sem_2022-4_release_notes.htm - Release Notes, Vendor Advisory
CWE CWE-436
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:solarwinds:security_event_manager:*:*:*:*:*:*:*:*

23 Nov 2022, 18:32

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-23 17:15

Updated : 2024-02-04 23:14


NVD link : CVE-2022-38115

Mitre link : CVE-2022-38115

CVE.ORG link : CVE-2022-38115


JSON object : View

Products Affected

solarwinds

  • security_event_manager
CWE
CWE-436

Interpretation Conflict

CWE-650

Trusting HTTP Permission Methods on the Server Side