Oracle Solaris Cluster vulnerabilities

14 known vulnerabilities affecting oracle/solaris_cluster.

Total CVEs
14
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM6LOW3

Vulnerabilities

Page 1 of 1
CVE-2020-6950MEDIUMCVSS 6.5PoCv4.02021-06-02
CVE-2020-6950 [MEDIUM] CWE-22 CVE-2020-6950: Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via th Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
nvd
CVE-2021-29425MEDIUMCVSS 4.8v4.02021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2019-17195CRITICALCVSS 9.8v4.02019-10-15
CVE-2019-17195 [CRITICAL] CWE-755 CVE-2019-17195: Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, wh Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
nvd
CVE-2019-10086HIGHCVSS 7.3v4.42019-08-20
CVE-2019-10086 [HIGH] CWE-502 CVE-2019-10086: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressi In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
nvd
CVE-2018-2930CRITICALCVSS 9.8v3.3v4.32018-07-18
CVE-2018-2930 [CRITICAL] CVE-2018-2930: Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: N Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). Supported versions that are affected are 3.3 and 4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via RPC to compromise Solaris Cluster. Successful attacks of this vulnerability can result in takeo
nvd
CVE-2018-2822MEDIUMCVSS 6.6v4.32018-04-19
CVE-2018-2822 [MEDIUM] CVE-2018-2822: Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: C Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: Cluster Geo). The supported version that is affected is 4.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris Cluster executes to compromise Solaris Cluster. Successful attacks of this vulnerability c
nvd
CVE-2017-3588HIGHCVSS 7.3v3.3v4.32017-10-19
CVE-2017-3588 [HIGH] CVE-2017-3588: Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: H Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: HA for MySQL). Supported versions that are affected are 3.3 and 4.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris Cluster executes to compromise Solaris Cluster. Successful attacks require human in
nvd
CVE-2017-10234HIGHCVSS 7.3v4.02017-08-08
CVE-2017-10234 [HIGH] CVE-2017-10234: Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: N Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris Cluster executes to compromise Solaris Cluster. Successful attacks require human int
nvd
CVE-2016-5551LOWCVSS 2.8v4.32017-04-24
CVE-2016-5551 [LOW] CWE-284 CVE-2016-5551: Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: N Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4.3. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris Cluster executes to compromise Solaris Cluster. Successful attacks require
nvd
CVE-2016-5508LOWCVSS 3.3v4.32016-10-25
CVE-2016-5508 [LOW] CWE-200 CVE-2016-5508: Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 4.3 Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 4.3 allows local users to affect confidentiality via vectors related to Cluster Geo.
nvd
CVE-2016-5525LOWCVSS 3.3v3.3v4.32016-10-25
CVE-2016-5525 [LOW] CWE-254 CVE-2016-5525: Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect integrity via vectors related to Cluster check files.
nvd
CVE-2016-3480MEDIUMCVSS 4.4v3.3v4.32016-07-21
CVE-2016-3480 [MEDIUM] CVE-2016-3480: Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect confidentiality via vectors related to HA for Postgresql.
nvd
CVE-2016-0417MEDIUMCVSS 4.6v3.3v4.22016-01-21
CVE-2016-0417 [MEDIUM] CVE-2016-0417: Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.2 allows local users to affect confidentiality, integrity, and availability via vectors related to HA for MySQL.
nvd
CVE-2011-2297MEDIUMCVSS 6.1v3.32011-07-21
CVE-2011-2297 [MEDIUM] CVE-2011-2297: Unspecified vulnerability in Oracle Solaris Cluster 3.3 allows local users to affect confidentiality Unspecified vulnerability in Oracle Solaris Cluster 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Data Service for WebLogic Server.
nvd