Impact
The Filesystems component of Oracle Solaris 11.4 contains a flaw that permits a low‑privileged local user to create, delete, or alter critical data, thereby compromising system integrity. Additionally, successful exploitation can cause the operating system to hang or crash repeatedly, leading to a denial‑of‑service condition. The vulnerability carries a CVSS 3.1 score of 7.1 with an Impact vector of Integrity and Availability, and requires no user interaction.
Affected Systems
Oracle Solaris 11.4 is the only version explicitly listed as affected. Deployments of this release, unless patched by Oracle, are vulnerable, and the issue is confined to the Solaris environment on Oracle platforms.
Risk and Exploitability
The moderate‑to‑high CVSS score indicates a serious potential impact. The EPSS score of less than 1% suggests that, as of the latest data, the likelihood of exploitation is low, and the vulnerability is not catalogued as a known exploited vulnerability by CISA. However, because the flaw can be triggered by a local attacker with low privileges, any user who has logged onto the system can initiate the integrity and availability effects identified in the description.
OpenCVE Enrichment