PT-2024-3525 · Oracle · Oracle Solaris

Published

2024-04-16

·

Updated

2025-03-13

·

CVE-2024-21059

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Solaris version 11
Description The issue is related to insufficient access controls in the Utility component of Oracle Solaris, allowing a low-privileged attacker with logon access to the infrastructure to compromise the system. Successful attacks can result in the takeover of Oracle Solaris and may significantly impact additional products.
Recommendations For Oracle Solaris version 11, update the system to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable Utility component to minimize the risk of exploitation.

Fix

Improper Privilege Management

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03827
CVE-2024-21059

Affected Products

Oracle Solaris