Oracle Solaris NSSwitch Vulnerability in Oracle Systems
CVE-2023-21896

7HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability exists in the NSSwitch component of Oracle Solaris that could allow a low-privileged attacker with access to the system to execute a successful exploit. This could potentially compromise the integrity and availability of Oracle Solaris, leading to unauthorized access and control over the affected infrastructure. The supported versions impacted by this vulnerability include Oracle Solaris 10 and 11. It is crucial for administrators to review security settings and apply necessary updates to safeguard their systems.

Affected Version(s)

Solaris Operating System 10

Solaris Operating System 11

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.