Unauthorized Access Vulnerability in Oracle ZFS Storage Appliance Kit by Oracle Systems
CVE-2021-2149

2.5LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

A vulnerability exists in the Oracle ZFS Storage Appliance Kit that enables low privileged users with a valid logon to exploit the system. This vulnerability allows these users to gain unauthorized access, potentially leading to insertion, update, or deletion of data within the appliance. Although the risk level is manageable, organizations using affected versions should prioritize patching to secure their data integrity and prevent unauthorized data manipulations.

Affected Version(s)

Sun ZFS Storage Appliance Kit (AK) Software 8.8

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.