cbcvebase.

Oracle Zfs Storage Appliance Kit vulnerabilities

117 known vulnerabilities affecting oracle/zfs_storage_appliance_kit.

Total CVEs
117
CISA KEV
3
actively exploited
Public exploits
6
Exploited in wild
4
Severity breakdown
CRITICAL18HIGH47MEDIUM47LOW5

Vulnerabilities

Page 6 of 6
CVE-2025-62477P4MEDIUMCVSS 4.9v8.82025-10-21
CVE-2025-62477 [MEDIUM] CWE-400 CVE-2025-62477: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote R Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can resu
nvd
CVE-2025-53046P4MEDIUMCVSS 4.9v8.82025-10-21
CVE-2025-53046 [MEDIUM] CWE-400 CVE-2025-53046: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytic Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in una
nvd
CVE-2025-62478P4MEDIUMCVSS 4.9v8.82025-10-21
CVE-2025-62478 [MEDIUM] CWE-400 CVE-2025-62478: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object S Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in
nvd
CVE-2025-62289P4MEDIUMCVSS 4.9v8.82025-10-21
CVE-2025-62289 [MEDIUM] CWE-267 CVE-2025-62289: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesyst Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in u
nvd
CVE-2024-21155P4MEDIUMCVSS 4.7v8.82024-07-16
CVE-2024-21155 [MEDIUM] CVE-2024-21155: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: User Int Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: User Interface). The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks require human interaction from a person ot
nvd
CVE-2019-13038P4MEDIUMCVSS 6.1v8.82019-06-29
CVE-2019-13038 [MEDIUM] CWE-601 CVE-2019-13038: mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrat mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
nvd
CVE-2021-4115P4MEDIUMCVSS 5.5v8.82022-02-21
CVE-2021-4115 [MEDIUM] CWE-400 CVE-2021-4115: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to proc There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
nvd
CVE-2022-21375P4MEDIUMCVSS 5.5v8.82022-01-19
CVE-2022-21375 [MEDIUM] CVE-2022-21375: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2023-21833P4MEDIUMCVSS 4.3v8.82024-02-17
CVE-2023-21833 [MEDIUM] CWE-200 CVE-2023-21833: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object S Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in u
nvd
CVE-2020-13632P4MEDIUMCVSS 5.5v8.82020-05-27
CVE-2020-13632 [MEDIUM] CWE-476 CVE-2020-13632: ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchin ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
nvd
CVE-2021-23839P4LOWCVSS 3.7v8.82021-02-16
CVE-2021-23839 [LOW] CWE-327 CVE-2021-23839: OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configur OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A
nvd
CVE-2021-4183P4MEDIUMCVSS 5.5v8.82021-12-30
CVE-2021-4183 [MEDIUM] CWE-125 CVE-2021-4183: Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
nvd
CVE-2024-20959P4MEDIUMCVSS 4.4v8.82024-01-16
CVE-2024-20959 [MEDIUM] CWE-400 CVE-2024-20959: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful at
nvd
CVE-2025-62479P4LOWCVSS 2.7v8.82025-10-21
CVE-2025-62479 [LOW] CWE-267 CVE-2025-62479: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block St Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in un
nvd
CVE-2022-21563P4LOWCVSS 3.4v8.82022-07-19
CVE-2022-21563 [LOW] CVE-2022-21563: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). T Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of
nvd
CVE-2025-62480P4LOWCVSS 2.7v8.82025-10-21
CVE-2025-62480 [LOW] CWE-267 CVE-2025-62480: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming S Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in
nvd
CVE-2024-20914P4LOWCVSS 2.3v8.82024-01-16
CVE-2024-20914 [LOW] CWE-200 CVE-2024-20914: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful attac
nvd
Oracle Zfs Storage Appliance Kit vulnerabilities | cvebase