First published: Sat Feb 17 2024(Updated: )
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle ZFS Storage Appliance Kit accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Storage Cloud Software Appliance | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21833 is considered easily exploitable, allowing low privileged attackers to compromise the Oracle ZFS Storage Appliance Kit.
To mitigate CVE-2023-21833, apply the latest security patches provided by Oracle for version 8.8 of the ZFS Storage Appliance Kit.
CVE-2023-21833 affects users of the Oracle ZFS Storage Appliance Kit version 8.8.
CVE-2023-21833 could allow unauthorized access to sensitive data within the Oracle ZFS Storage Appliance via network exploitation.
No authentication is required for an attacker to exploit CVE-2023-21833, making it a higher risk for affected systems.