CVE-2016-5449: High severity oracle integrated lights out manager vulnerability
Published Jul 21, 2016
·Updated
Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect availability via vectors related to Console Redirection.
Affected Software
3 affected components
ORACLE Integrated Lights Out Manager Firmware=3.0
ORACLE Integrated Lights Out Manager Firmware=3.1
ORACLE Integrated Lights Out Manager Firmware=3.2
Remediation
Event History
Jul 21, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5449?
CVE-2016-5449 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-5449?
To address CVE-2016-5449, upgrade to a patched version of the Oracle Integrated Lights Out Manager firmware.
3
What versions are affected by CVE-2016-5449?
CVE-2016-5449 affects Oracle Integrated Lights Out Manager firmware versions 3.0, 3.1, and 3.2.
4
What type of attacks does CVE-2016-5449 facilitate?
CVE-2016-5449 allows remote attackers to impact availability via console redirection vulnerabilities.
5
Is there a workaround for CVE-2016-5449?
While the primary mitigation is to update firmware, limiting remote access may act as a temporary workaround for CVE-2016-5449.