Unauthorized Access Vulnerability in Oracle ZFS Storage Appliance Kit by Oracle Systems
CVE-2021-2149
2.5LOW
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 22 April 2021
Summary
A vulnerability exists in the Oracle ZFS Storage Appliance Kit that enables low privileged users with a valid logon to exploit the system. This vulnerability allows these users to gain unauthorized access, potentially leading to insertion, update, or deletion of data within the appliance. Although the risk level is manageable, organizations using affected versions should prioritize patching to secure their data integrity and prevent unauthorized data manipulations.
Affected Version(s)
Sun ZFS Storage Appliance Kit (AK) Software 8.8
References
CVSS V3.1
Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved