PT-2022-2026 · Oracle · Oracle Solaris
Published
2022-01-19
·
Updated
2022-01-22
·
CVE-2022-21298
CVSS v3.1
3.9
Low
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Oracle Solaris version 11
Description
The issue is related to errors in the code of the Oracle Solaris installer, which can be exploited to gain access to modify, add, or delete data, or cause a partial denial of service. The vulnerability can be easily exploited by a low-privileged attacker with logon access to the infrastructure where Oracle Solaris is executed. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized access to some of Oracle Solaris' accessible data.
Recommendations
For Oracle Solaris version 11, update the installer to a version that fixes the code errors to prevent exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Solaris