Junglewise Threat Intelligence

CVE-2017-3242: Oracle VM Server for SPARC denial of service in LDOM Manager

CVE-2017-3242 · Severity: medium · CVSS 5.9 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A vulnerability exists in the LDOM Manager component of Oracle VM Server for SPARC, which is used to manage virtualized environments on Sun Systems. A local user with low-level access can exploit this flaw to cause the management server to hang or crash repeatedly. This results in a complete denial of service for the virtualization management layer, potentially impacting the availability of hosted services.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the LDOM Manager subcomponent of Oracle VM Server for SPARC. It is locally exploitable by an attacker with low privileges who has logon access to the infrastructure. Exploitation requires interaction from a user other than the attacker (UI:R) and can result in a complete denial of service (Availability: High) by causing the component to hang or crash. Notably, the vulnerability has a 'Changed' scope (S:C), indicating that the impact can extend beyond the LDOM Manager to other parts of the Sun Systems environment. Patches were released as part of the Oracle Critical Patch Update in January 2017.

Affected products

  • Oracle VM Server for SPARC 3.2, 3.4

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update

References