API Framework Vulnerability in Sun ZFS Storage Appliance Kit by Oracle
CVE-2018-2863

5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2018

Summary

A vulnerability exists in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite, particularly within the API frameworks. This flaw allows an attacker with low privileges and network access via HTTP to gain unauthorized read access to sensitive data. Although primarily affecting the Sun ZFS Storage Appliance Kit, this vulnerability may also impact other connected Oracle products. The risk associated with this exposure emphasizes the need for prompt security measures to safeguard accessible data.

Affected Version(s)

Sun ZFS Storage Appliance Kit (AK) Software < 8.7.17

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.