Rewterz

Rewterz Threat Alert – Sophisticated Covert Attack Campaign Targeting Military Contractors – Active IOCs

October 1, 2022
Rewterz

Rewterz Threat Advisory – Multiple Google Chrome V8 Vulnerabilities

October 1, 2022

Rewterz Threat Advisory – Multiple SolarWinds Orion Platform Vulnerabilities

Severity

High

Analysis Summary

CVE-2022-36965 CVSS:7.5
SolarWinds Orion Platform is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the QoE application input field. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2022-36961 CVSS:8
SolarWinds Orion Platform could allow a remote authenticated attacker to gain elevated privileges on the system, caused by flaw in the UpdateActionsDescriptions function. By sending specially-crafted SQL queries, an authenticated attacker could exploit this vulnerability to gain elevated privileges or execute arbitrary code on the system.

Impact

  • Cross-Site Scripting
  • Privilege Escalation

Indicators Of Compromise

CVE

  • CVE-2022-36965
  • CVE-2022-36961

Affected Vendors

SolarWinds

Affected Products

SolarWinds Orion Platform 2022.2

Remediation

Upgrade to the latest version of SolarWinds Platform, available from the SolarWinds Web site.

SolarWinds Website

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.