Kernel Vulnerability in Oracle Solaris by Oracle Systems
CVE-2022-21493

5.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

A vulnerability exists within Oracle Solaris, specifically in its kernel component, allowing low-privileged attackers with access to systems where Oracle Solaris runs to exploit it. Although exploitation requires user interaction from a third party, the consequences can be severe, potentially leading to system hangs or frequent crashes that disrupt service availability. Such incidents can have further implications on other interconnected products, thereby underscoring the necessity for robust security measures. Immediate action is recommended to mitigate the risk associated with this vulnerability.

Affected Version(s)

Solaris Operating System 11

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.