Denial of Service Vulnerability in Sun ZFS Storage Appliance by Oracle
CVE-2023-22130

5.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

A vulnerability exists in the Sun ZFS Storage Appliance by Oracle that allows an unauthenticated attacker with network access via HTTP to exploit the system. This vulnerability can lead to the unauthorized ability to cause a hang or frequent crashes of the appliance, resulting in a denial of service. Users of the affected version 8.8.60 should apply necessary patches to mitigate exposure to this issue.

Affected Version(s)

Sun ZFS Storage Appliance Kit (AK) Software 8.8.60

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.