PT-2024-1188 · Oracle · Oracle Zfs Storage Appliance Kit

Published

2024-01-16

·

Updated

2024-01-20

·

CVE-2024-20914

CVSS v3.1

2.3

Low

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle ZFS Storage Appliance Kit version 8.8
Description The issue is related to insufficient input validation in the Core component of the Oracle ZFS Storage Appliance Kit. This allows a high-privileged attacker with logon to the infrastructure to compromise the Oracle ZFS Storage Appliance Kit, resulting in unauthorized read access to a subset of accessible data.
Recommendations For version 8.8, update to a version that includes the fix for this issue, as the current version allows for easy exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-00515
CVE-2024-20914

Affected Products

Oracle Zfs Storage Appliance Kit