CVE-2018-2611
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: Core Services). The supported version that is affected is Prior to 8.7.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance Kit (AK). While the vulnerability is in Sun ZFS Storage Appliance Kit (AK), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVSS Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| oracle | sun_zfs_storage_appliance_kit | * < 8.7.13 |
GitHub Security Advisory GHSA-9q8m-jmvc-rf46
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products...
References (6)
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Patch, Vendor Advisory
- http://www.securityfocus.com/bid/102587 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040215 Third Party Advisory, VDB Entry
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Patch, Vendor Advisory
- http://www.securityfocus.com/bid/102587 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040215 Third Party Advisory, VDB Entry
Risk Scores
Top 18% most likely to be exploited