PT-2018-15616 · Oracle · Integrated Lights Out Manager+1

Publicado

2018-01-18

·

Atualizado

2019-10-03

·

CVE-2018-2566

CVSS v3.1

7.7

Alta

VetorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Oracle Sun Systems Products Suite versions 3.x and 4.x
Description The issue affects the Integrated Lights Out Manager (ILOM) component, specifically the Remote Console Application. It can be exploited by a low-privileged attacker with network access via TLS, but it is difficult to exploit and requires human interaction from someone other than the attacker. Successful attacks can compromise the ILOM and may significantly impact additional products, allowing unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all ILOM accessible data.
Recommendations For versions 3.x and 4.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-2566

Produtos afetados

Integrated Lights Out Manager
Oracle Sun Systems Products Suite