Deserialization of Untrusted Data in Resource Controls Remote Code Execution
43Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.9epss 81%
exploitation probability
81%top 1% of all CVEs
observed exploitation
nono source reports it
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Affected products
SolarWinds · Patch Manager