PT-2022-2026 · Oracle · Oracle Solaris

Published

2022-01-19

·

Updated

2022-01-22

·

CVE-2022-21298

CVSS v3.1

3.9

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Oracle Solaris version 11
Description The issue is related to errors in the code of the Oracle Solaris installer, which can be exploited to gain access to modify, add, or delete data, or cause a partial denial of service. The vulnerability can be easily exploited by a low-privileged attacker with logon access to the infrastructure where Oracle Solaris is executed. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized access to some of Oracle Solaris' accessible data.
Recommendations For Oracle Solaris version 11, update the installer to a version that fixes the code errors to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01622
CVE-2022-21298

Affected Products

Oracle Solaris