PT-2020-1502 · Oracle · Oracle Vm Server For Sparc

Published

2020-01-14

·

Updated

2022-07-08

·

CVE-2020-2571

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle VM Server for SPARC version 3.6
Description The issue is related to insufficient access control in the Templates component of Oracle VM Server for SPARC, allowing an attacker to gain unauthorized access to protected information. An easily exploitable vulnerability in Oracle VM Server for SPARC can be compromised by an unauthenticated attacker with logon to the infrastructure where Oracle VM Server for SPARC executes. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized update, insert, or delete access to some of Oracle VM Server for SPARC's accessible data.
Recommendations For Oracle VM Server for SPARC version 3.6, consider restricting access to the Templates component until a patch is available. As a temporary workaround, limit the interaction with the infrastructure where Oracle VM Server for SPARC executes to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00485
CVE-2020-2571

Affected Products

Oracle Vm Server For Sparc