#VU47887 Improper input validation in Oracle Solaris - CVE-2020-14871
Published: October 23, 2020 / Updated: December 26, 2021
Oracle Solaris
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Pluggable authentication module (PAM) component in Oracle Solaris. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Note, this vulnerability is being actively exploited in the wild.