PT-2020-2640 · Oracle · Oracle Solaris

Marco Ivaldi

·

Published

2020-04-15

·

Updated

2022-06-30

·

CVE-2020-2851

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Solaris versions 10 and 11
Description The issue is related to insufficient input validation in the Common Desktop Environment component of Oracle Solaris. This can be exploited by an attacker to gain full control over the application. The vulnerability is difficult to exploit and requires a low-privileged attacker with logon access to the infrastructure where Oracle Solaris is executed. Successful exploitation can result in the takeover of Oracle Solaris and may have significant impacts on additional products.
Recommendations For Oracle Solaris versions 10 and 11, update to a version that includes the fix for this issue to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02679
CVE-2020-2851

Affected Products

Oracle Solaris