Lucene search

K
symantecSymantec Security ResponseSMNTC-111550
HistoryJan 14, 2020 - 12:00 a.m.

Oracle Solaris CVE-2020-2696 Local Security Vulnerability

2020-01-1400:00:00
Symantec Security Response
www.symantec.com
25

0.001 Low

EPSS

Percentile

46.0%

Description

Oracle Solaris is prone to a local security vulnerability. This issue affects the ‘Common Desktop Environment’ component. This vulnerability affects the following supported version: 10

Technologies Affected

  • Oracle Solaris 10

Recommendations

Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells.
Grant local interactive access to affected computers for trusted and accountable users only.

Block external access at the network boundary, unless external parties require service.
Filter access to the affected computer at the network boundary if global access isn’t needed. Restricting access to only trusted computers and networks might greatly reduce the likelihood of a successful exploit.

Permit privileged access for trusted individuals only.
Permitting privileged access to known and trusted individuals only may limit the exposure to this and other latent vulnerabilities.

Run all software as a nonprivileged user with minimal access rights.
To limit the impact of latent vulnerabilities, configure servers and other applications to run as a nonadministrative user with minimal access rights.

Updates are available. Please see the references or vendor advisory for more information.

CPENameOperatorVersion
oracle solariseq10