CVE-2018-2858: Medium severity oracle storage cloud software appliance vulnerability
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: HTTP data path subsystems). The supported version that is affected is Prior to 8.7.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance Kit (AK). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Sun ZFS Storage Appliance Kit (AK) accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is vulnerability CVE-2018-2858?
Vulnerability CVE-2018-2858 is a vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite.
What is the severity of vulnerability CVE-2018-2858?
The severity of vulnerability CVE-2018-2858 is medium with a CVSS score of 5.3.
Who is affected by vulnerability CVE-2018-2858?
Anyone using the Sun ZFS Storage Appliance Kit prior to version 8.7.17 is affected by vulnerability CVE-2018-2858.
How can an attacker exploit vulnerability CVE-2018-2858?
An unauthenticated attacker with network access via HTTP can easily exploit vulnerability CVE-2018-2858.
Is there a patch available for vulnerability CVE-2018-2858?
Yes, Oracle has released a patch for vulnerability CVE-2018-2858. It is recommended to update to version 8.7.17 or later.