Oracle ZFS Storage Appliance Kit Vulnerability Allows Low Privileged Attackers to Compromise Data
CVE-2023-21833

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 February 2024

Summary

A vulnerability has been identified in the Object Store component of the Oracle ZFS Storage Appliance Kit. This flaw allows a low privileged attacker with network access via HTTP to exploit the system. Successful exploitation can lead to unauthorized read access to sensitive data within the Oracle ZFS Storage Appliance Kit, compromising data confidentiality. It is essential for users to assess their security measures to mitigate the potential risks associated with this vulnerability.

Affected Version(s)

Sun ZFS Storage Appliance Kit (AK) Software 8.8

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.