CVE-2022-38112
CVE-2022-38112 is a high-severity vulnerability in Solarwinds Database Performance Analyzer with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-312.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 0% (34th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-312
- Affected product: Solarwinds Database Performance Analyzer
- Published:
- Last modified:
Description
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
Frequently asked questions
- What is CVE-2022-38112?
- In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
- How severe is CVE-2022-38112?
- CVE-2022-38112 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2022-38112 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (34th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-38112?
- CVE-2022-38112 affects Solarwinds Database Performance Analyzer. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2022-38112?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2022-38112 published?
- CVE-2022-38112 was published on 2023-01-20 and last updated on 2026-06-17.
References
- https://documentation.solarwinds.com/en/success_center/dpa/content/release_notes/dpa_2023-1_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-38112
Affected products (1)
- cpe:2.3:a:solarwinds:database_performance_analyzer:*:*:*:*:*:*:*:*
More vulnerabilities in Solarwinds Database Performance Analyzer
- CVE-2023-23837 — High (CVSS 7.5): No exception handling vulnerability which revealed sensitive or excessive information to users.
- CVE-2021-35229 — Medium (CVSS 6.8): Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when…
- CVE-2023-23838 — Medium (CVSS 6.5): Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the…
- CVE-2023-33231 — Medium (CVSS 6.1): XSS attack was possible in DPA 2023.2 due to insufficient input validation
- CVE-2018-19386 — Medium (CVSS 6.1): SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component,…
- CVE-2025-26398 — Medium (CVSS 5.6): SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this…
All CVEs affecting Solarwinds Database Performance Analyzer →
Other CWE-312 (Cleartext Storage of Sensitive Information) vulnerabilities
- CVE-2022-43757 — Critical (CVSS 9.9): A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain…
- CVE-2021-36782 — Critical (CVSS 9.9): A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster…
- CVE-2020-9045 — Critical (CVSS 9.9): During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management…
- CVE-2026-81321 — Critical (CVSS 9.8): CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker…
- CVE-2026-15721 — Critical (CVSS 9.8): Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST…
- CVE-2026-31848 — Critical (CVSS 9.8): Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which…
Browse all CWE-312 (Cleartext Storage of Sensitive Information) vulnerabilities →