Executive brief
A critical out-of-bounds write vulnerability in the Pluggable Authentication Module (PAM) component of Oracle Solaris allows unauthenticated attackers to compromise the system via multiple protocols. Successful exploitation can lead to a complete takeover of the affected Oracle Solaris or ZFS Storage Appliance systems.
Affected products
- Oracle Solaris 10, 11 (prior to 11.1)
- Oracle ZFS Storage Appliance Kit Prior to 8.7
Timeline
- 2020-10-20: advisory: Initial Oracle security alert published
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2021-11-03: disclosed: NVD publication date
- 2021-11-03: exploited: Confirmed as exploited in the wild per CISA KEV catalog