Vulnerability in Oracle ZFS Storage Appliance Kit by Oracle Systems
CVE-2021-1999

5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 January 2021

Summary

A vulnerability has been identified in the Oracle ZFS Storage Appliance Kit associated with the RAS subsystems. This vulnerability allows an attacker with high privileges, who has logged onto the infrastructure where the appliance runs, to potentially compromise the system. Successful exploitation requires human interaction from another individual, making the attack vector particularly intricate. While the core vulnerability lies within the Oracle ZFS Storage Appliance Kit, the ramifications of an attack could extend to other connected products, leading to unauthorized creation, deletion, or modification of critical data accessible by the appliance.

Affected Version(s)

Sun ZFS Storage Appliance Kit (AK) Software 8.8

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.