HIGH🇬🇧 English

CVE-2019-9579

CVSS 8.1v3.1pub. 2022-12-26upd. 2025-04-14

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Illumos

    APP
    Illumos
    wszystkie wersje
  • Nexenta Nexentastor

    APP
    Nexenta
    4.0.55.1.2
  • Oracle Solaris

    OS
    Oracle
    11
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-14871CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Oracle Solaris PAM — zdalne przejęcie systemu bez uwierzytelnienia

CVE-2013-2251CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Apache Struts 2: RCE przez prefiks action/redirect w parametrach

CVE-2026-46978CRITICAL10.0PL ✓ten sam produkt

Auth Bypass w Oracle Solaris Remote Administration Daemon (CVSS 10.0)

CVE-2025-36038CRITICAL9.0PL ✓ten sam produkt

RCE w IBM WebSphere Application Server przez niebezpieczną deserializację

CVE-2021-39085CRITICAL9.8PL ✓ten sam produkt

SQL Injection w IBM Sterling B2B Integrator — nieautoryzowany dostęp do bazy danych