Executive brief
A vulnerability exists in the kernel of the Oracle Solaris operating system, which is used to manage hardware resources and run enterprise applications. An attacker with local access to the system could trick a legitimate user into performing an action that allows the attacker to modify or delete certain system data. While this could impact the integrity of information on the server, it does not directly allow for the theft of data or a complete system shutdown.
Technical details
A vulnerability in the Kernel subcomponent of Oracle Solaris version 11.3 allows for unauthorized data modification. The flaw is classified as easily exploitable but requires a local logon to the infrastructure where Solaris executes. A successful exploit requires human interaction from a person other than the attacker (User Interaction: Required). The impact is limited to unauthorized update, insert, or delete access to some Solaris-accessible data, resulting in a low integrity impact with no impact on confidentiality or availability. The vulnerability is tracked as CVE-2017-3301 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Solaris 11.3
Timeline
- 2017-01-27: advisory: Initial disclosure by Oracle
- 2017-01-27: disclosed