SB2017012825 - Improper access control in Oracle Solaris 



SB2017012825 - Improper access control in Oracle Solaris

Published: January 28, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017012825
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2016-8330)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Solaris accessible data. CVSS v3.0 Base Score 3.7 (Integrity impacts).


Remediation

Install update from vendor's website.