CVE-1999-1426
published 1997-11-10CVE-1999-1426: Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.
PriorityP49medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.28%
19.9th percentile
Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | solstice_adminsuite | — | — |
| sun | solstice_adminsuite | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun Solaris 2.4/2.5/2.5.1 Solstice AdminSuite privileges management (ID 00145 / BID-208)
vuldb·2026-04-17·CVSS 6.2
CVE-1999-1426 [MEDIUM] Sun Solaris 2.4/2.5/2.5.1 Solstice AdminSuite privileges management (ID 00145 / BID-208)
A vulnerability identified as problematic has been detected in Sun Solaris 2.4/2.5/2.5.1. This impacts an unknown function of the component Solstice AdminSuite. This manipulation causes improper privilege management.
This vulnerability appears as CVE-1999-1426. The attack requires local access. There is no available exploit.
You should upgrade the affected component.
GHSA
GHSA-552p-f4h5-wjj9: Solaris Solstice AdminSuite (AdminSuite) 2
ghsa_unreviewed·2022-04-30
CVE-1999-1426 [MEDIUM] GHSA-552p-f4h5-wjj9: Solaris Solstice AdminSuite (AdminSuite) 2
Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1997-11-10
Published