Vulnerability Description
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Server And Application Monitor | 2022.4 |
Related Weaknesses (CWE)
References
- https://documentation.solarwinds.com/en/success_center/sam/content/release_notesRelease Notes
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-47508Vendor Advisory
- https://documentation.solarwinds.com/en/success_center/sam/content/release_notesRelease Notes
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-47508Vendor Advisory
FAQ
What is CVE-2022-47508?
CVE-2022-47508 is a vulnerability with a CVSS score of 7.5 (HIGH). Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing K...
How severe is CVE-2022-47508?
CVE-2022-47508 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-47508?
Check the references section above for vendor advisories and patch information. Affected products include: Solarwinds Server And Application Monitor.