CVE-2022-21563: Low severity oracle storage cloud software appliance vulnerability
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle ZFS Storage Appliance Kit accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 3.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Oracle ZFS Storage Appliance Kit vulnerability?
The vulnerability ID for this Oracle ZFS Storage Appliance Kit vulnerability is CVE-2022-21563.
What is the affected software version of this vulnerability?
The affected software version of this vulnerability is Oracle ZFS Storage Appliance Kit 8.8.
What is the severity rating of CVE-2022-21563?
The severity rating of CVE-2022-21563 is low (3.4).
How can this vulnerability be exploited?
This vulnerability can be easily exploited by a high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise the system.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the official Oracle Security Alerts website: https://www.oracle.com/security-alerts/cpujul2022.html