API Framework Vulnerability in Sun ZFS Storage Appliance Kit by Oracle
CVE-2018-2863
5MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 April 2018
Summary
A vulnerability exists in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite, particularly within the API frameworks. This flaw allows an attacker with low privileges and network access via HTTP to gain unauthorized read access to sensitive data. Although primarily affecting the Sun ZFS Storage Appliance Kit, this vulnerability may also impact other connected Oracle products. The risk associated with this exposure emphasizes the need for prompt security measures to safeguard accessible data.
Affected Version(s)
Sun ZFS Storage Appliance Kit (AK) Software < 8.7.17
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved