Junglewise Threat Intelligence

CVE-2016-8330: Oracle Solaris integrity vulnerability in Kernel

CVE-2016-8330 · Severity: low · CVSS 3.7 · Published 2017-01-27

Technologies: Oracle Solaris. Vendors: Oracle.

Executive brief

A vulnerability exists in the kernel of Oracle Solaris 11.3, the core component of the operating system that manages system resources. An unauthenticated attacker could potentially exploit this flaw over a network to make unauthorized changes to system data. While the vulnerability is difficult to exploit, it could lead to unauthorized updates or deletions of sensitive information.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Oracle Solaris Kernel. It allows an unauthenticated attacker with network access via multiple protocols to potentially perform unauthorized update, insert, or delete operations on Solaris accessible data. The exploit complexity is rated as high, suggesting that specific timing or environmental conditions must be met for a successful attack. The impact is limited to integrity, with no reported impact on confidentiality or availability. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Solaris 11.3

Timeline

  • 2017-01-27: disclosed: Initial NVD publication
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats