PT-2018-2426 · Oracle · Oracle Solaris+1

Publicado

2018-10-16

·

Atualizado

2019-10-03

·

CVE-2018-3267

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Solaris version 11.3
Description The issue is related to inadequate access control in the LFTP component of Oracle Solaris, allowing a remote attacker to gain unauthorized access to data via the FTP protocol. This can result in unauthorized read access to a subset of Solaris accessible data.
Recommendations For Oracle Solaris version 11.3, consider restricting access to the LFTP component until a patch is available. As a temporary workaround, limit the use of the FTP protocol to minimize the risk of exploitation.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00627
CVE-2018-3267

Produtos afetados

Lftp
Oracle Solaris