First published: Wed Jul 18 2018(Updated: )
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). Supported versions that are affected are 3.3 and 4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via RPC to compromise Solaris Cluster. Successful attacks of this vulnerability can result in takeover of Solaris Cluster. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris Cluster | =3.3 | |
Oracle Solaris Cluster | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Solaris Cluster vulnerability is CVE-2018-2930.
The affected software of this vulnerability is Oracle Solaris Cluster versions 3.3 and 4.3.
This vulnerability has a severity rating of 9.8, which is considered critical.
An unauthenticated attacker with network access via RPC can exploit this vulnerability to compromise Solaris Cluster.
Yes, Oracle has released patches and solutions for this vulnerability. Please refer to the provided references for more information.