Security restrictions bypass in ILOM - CVE-2016-5448

 

Security restrictions bypass in ILOM - CVE-2016-5448

Published: July 21, 2016 / Updated: November 22, 2018


Vulnerability identifier: #VU190
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5448
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify data and cause partial denial of service.

The vulnerability exists in ILOM SNMP component. A remote authenticated attacker can partially modify data and cause partial denial of service conditions by exploiting a flaw in the ILOM SNMP component.

Successful exploitation of this vulnerability may result in modification of system information and partial denial of service conditions.

Affected software

ILOM

How to mitigate CVE-2016-5448

The vendor has issued a fix as part of the July 2016 Oracle Critical Patch Update.


External References

Related Security Bulletins