Solaris 10 (x86) : 147674-11

This script is Copyright (C) 2012-2017 Tenable Network Security, Inc.


Synopsis :

The remote host is missing Sun Security Patch number 147674-11

Description :

Vulnerability in the Solaris component of Oracle Sun Systems Products
Suite (subcomponent: Oracle Java Web Console). The supported version
that is affected is 10. Easily exploitable vulnerability allows low
privileged attacker with logon to the infrastructure where Solaris
executes to compromise Solaris. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Solaris accessible data as well as unauthorized read
access to a subset of Solaris accessible data and unauthorized ability
to cause a partial denial of service (partial DOS) of Solaris.

See also :

https://getupdates.oracle.com/readme/147674-11

Solution :

You should install this patch for your system to be up-to-date.

Risk factor :

Medium / CVSS Base Score : 4.6
(CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 4.0
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Solaris Local Security Checks

Nessus Plugin ID: 58737 ()

Bugtraq ID: 63078
64859

CVE ID: CVE-2013-5839
CVE-2014-0390
CVE-2017-10062

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now