CVE-2023-21833

Severity
4.3MEDIUM
EPSS
0.3%
top 49.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17

Description

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle ZFS Storage Appliance Kit accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vect

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

🔴Vulnerability Details

2
GHSA
GHSA-7q9h-g4j7-9vvh: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store)2024-02-17
CVEList
CVE-2023-21833: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store)2024-02-17

📋Vendor Advisories

1
Oracle
Oracle Oracle Systems Risk Matrix: Object Store — CVE-2023-218332024-01-15