PT-2018-2426 · Oracle · Oracle Solaris+1
Published
2018-10-16
·
Updated
2019-10-03
·
CVE-2018-3267
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Solaris version 11.3
Description
The issue is related to inadequate access control in the LFTP component of Oracle Solaris, allowing a remote attacker to gain unauthorized access to data via the FTP protocol. This can result in unauthorized read access to a subset of Solaris accessible data.
Recommendations
For Oracle Solaris version 11.3, consider restricting access to the LFTP component until a patch is available. As a temporary workaround, limit the use of the FTP protocol to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lftp
Oracle Solaris