PT-2018-15616 · Oracle · Integrated Lights Out Manager+1
Published
2018-01-18
·
Updated
2019-10-03
·
CVE-2018-2566
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Sun Systems Products Suite versions 3.x and 4.x
Description
The issue affects the Integrated Lights Out Manager (ILOM) component, specifically the Remote Console Application. It can be exploited by a low-privileged attacker with network access via TLS, but it is difficult to exploit and requires human interaction from someone other than the attacker. Successful attacks can compromise the ILOM and may significantly impact additional products, allowing unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all ILOM accessible data.
Recommendations
For versions 3.x and 4.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Integrated Lights Out Manager
Oracle Sun Systems Products Suite