PT-2020-1507 · Oracle · Oracle Solaris

Bengt Jonsson

+4

·

Published

2020-01-14

·

Updated

2022-07-28

·

CVE-2020-2565

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Solaris version 11
Description The issue is related to inadequate access control in the Consolidation Infrastructure component of Oracle Solaris, allowing a low-privileged attacker with logon access to the infrastructure to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker and can significantly impact additional products, potentially resulting in the takeover of Oracle Solaris.
Recommendations For Oracle Solaris version 11, consider restricting access to the Consolidation Infrastructure component to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00490
CVE-2020-2565

Affected Products

Oracle Solaris