First published: Tue Jan 16 2024(Updated: )
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle ZFS Storage Appliance Kit accessible data. CVSS 3.1 Base Score 2.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Storage Cloud Software Appliance | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20914 is categorized as an easily exploitable vulnerability that poses a risk to high-privileged attackers.
To mitigate CVE-2024-20914, users should apply the latest security patches provided by Oracle for the affected version 8.8.
Users of Oracle ZFS Storage Appliance Kit version 8.8 are affected by CVE-2024-20914.
CVE-2024-20914 involves the Core component of the Oracle ZFS Storage Appliance Kit.
CVE-2024-20914 requires the attacker to have logon access to the infrastructure where the Oracle ZFS Storage Appliance Kit runs, limiting remote exploitability.