PT-2017-16016 · Oracle · Sun Zfs Storage Appliance Kit

Published

2017-04-24

·

Updated

2019-10-03

·

CVE-2017-3585

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Sun Systems Products Suite versions AK 2013
Description The issue affects the User Interface subsystem of the Sun ZFS Storage Appliance Kit (AK) component, allowing an unauthenticated attacker with network access via HTTP to compromise the system. This can result in unauthorized access to update, insert, or delete some of the accessible data.
Recommendations For version AK 2013, update to a version that addresses this issue, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the User Interface subsystem to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-3585

Affected Products

Sun Zfs Storage Appliance Kit