vendor:
Solaris
by:
7.5
CVSS
HIGH
Local Information Disclosure
200
CWE
Product Name: Solaris
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: o:sun:solaris
Platforms Tested:
Local Information Disclosure Vulnerability in Sun Microsystems Solaris
The vulnerability allows a local attacker to access sensitive information, including superuser password information, leading to further attacks. A complete compromise is possible. An example exploit is available: $ /opt/SUNWsrspx/bin/srsexec -dvb /etc/shadow OWNED
Mitigation:
Apply the latest security patches provided by Sun Microsystems. Restrict local access to trusted users only.