CVE-2018-2930: Critical severity oracle solaris cluster vulnerability
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). Supported versions that are affected are 3.3 and 4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via RPC to compromise Solaris Cluster. Successful attacks of this vulnerability can result in takeover of Solaris Cluster. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Solaris Cluster vulnerability?
The vulnerability ID of this Solaris Cluster vulnerability is CVE-2018-2930.
What is the affected software of this vulnerability?
The affected software of this vulnerability is Oracle Solaris Cluster versions 3.3 and 4.3.
How severe is this vulnerability?
This vulnerability has a severity rating of 9.8, which is considered critical.
How can an attacker exploit this vulnerability?
An unauthenticated attacker with network access via RPC can exploit this vulnerability to compromise Solaris Cluster.
Is there a patch or solution available for this vulnerability?
Yes, Oracle has released patches and solutions for this vulnerability. Please refer to the provided references for more information.