Vulnerability in Oracle Solaris NSSwitch Component Affects Multiple Oracle Products
CVE-2023-21900

4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2023

Summary

This vulnerability affects Oracle Solaris, specifically within the NSSwitch component, allowing high privileged attackers with network access to exploit it. Although the attack requires human interaction from an individual other than the attacker, it poses a significant risk to all Oracle Solaris users. Successful exploitation can lead to unauthorized updates, inserts, or deletes of sensitive data and may result in a partial denial of service, hindering system functionality. Affected versions are Oracle Solaris 10 and 11, and the scope of potential impact can extend beyond just this platform.

Affected Version(s)

Solaris Operating System 10

Solaris Operating System 11

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.