Vulnerability in Oracle ZFS Storage Appliance Kit by Oracle Systems
CVE-2021-1999
5MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 January 2021
Summary
A vulnerability has been identified in the Oracle ZFS Storage Appliance Kit associated with the RAS subsystems. This vulnerability allows an attacker with high privileges, who has logged onto the infrastructure where the appliance runs, to potentially compromise the system. Successful exploitation requires human interaction from another individual, making the attack vector particularly intricate. While the core vulnerability lies within the Oracle ZFS Storage Appliance Kit, the ramifications of an attack could extend to other connected products, leading to unauthorized creation, deletion, or modification of critical data accessible by the appliance.
Affected Version(s)
Sun ZFS Storage Appliance Kit (AK) Software 8.8
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved