PT-2020-2641 · Oracle · Oracle Solaris

Published

2020-04-15

·

Updated

2020-04-16

·

CVE-2020-2927

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Solaris versions 10 and 11
Description The issue is related to insufficient input validation in the Common Desktop Environment component of Oracle Solaris. This allows a low-privileged attacker with logon access to the infrastructure where Oracle Solaris is executed to potentially compromise Oracle Solaris. Successful exploitation can result in the takeover of Oracle Solaris. The impact of this issue may also significantly affect additional products.
Recommendations For Oracle Solaris versions 10 and 11, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02680
CVE-2020-2927

Affected Products

Oracle Solaris