Slide 14
Slide 14 text
おまけ
最近のSolarisの脆弱性
CVE-2023-22003
• Vulnerability in the Oracle Solaris product of Oracle
Systems (component: Utility).
• Supported versions that are affected are 10 and 11.
• Easily exploitable vulnerability allows unauthenticated
attacker with logon to the infrastructure where Oracle
Solaris executes to compromise Oracle Solaris.
• Successful attacks require human interaction from a
person other than the attacker.
• Successful attacks of this vulnerability can result in
unauthorized update, insert or delete access to some of
Oracle Solaris accessible data.
• CVSS 3.1 Base Score 3.3 (Integrity impacts). CVSS Vector:
(CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
CVE-2024-20999
• Vulnerability in the Oracle Solaris product of Oracle
Systems (component: Zones).
• The supported version that is affected is 11.
• Easily exploitable vulnerability allows high privileged
attacker with logon to the infrastructure where Oracle
Solaris executes to compromise Oracle Solaris.
• While the vulnerability is in Oracle Solaris, attacks may
significantly impact additional products (scope change).
• Successful attacks of this vulnerability can result in
takeover of Oracle Solaris.
• CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and
Availability impacts). CVSS Vector:
(CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
© 2010-2024 Cloud Security Alliance Japan Chapter 14
https://nvd.nist.gov/vuln/detail/cve-2023-22003
https://nvd.nist.gov/vuln/detail/cve-2024-20999