PT-2023-9314 · Oracle · Oracle Solaris

Published

2023-12-07

·

Updated

2024-12-05

·

CVE-2024-21151

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Oracle Solaris version 11
Description The issue is related to insufficient input validation in the Filesystem component of Oracle Solaris, allowing a low-privileged attacker with logon access to the infrastructure to compromise Oracle Solaris. Successful attacks can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris.
Recommendations For Oracle Solaris version 11, update to a version that includes the fix for this issue, as the current version is affected and can be exploited to cause a partial denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06225
CVE-2024-21151

Affected Products

Oracle Solaris