Description
This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS.

Published: 2022-11-23
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

SolarWinds advises to upgrade to the latest version of SolarWinds SEM version 2022.4

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-40716 This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS.
History

Fri, 25 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Solarwinds Security Event Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2025-04-25T20:28:24.632Z

Reserved: 2022-08-09T00:00:00.000Z

Link: CVE-2022-38114

cve-icon Vulnrichment

Updated: 2024-08-03T10:45:52.893Z

cve-icon NVD

Status : Modified

Published: 2022-11-23T17:15:10.167

Modified: 2026-06-17T04:56:07.967

Link: CVE-2022-38114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')