Oracle
Oracle ZFS Storage Appliance KIT: vulnerabilidades y CVE
Oracle ZFS Storage Appliance KIT tiene 117 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 18 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE117
Últimos 12 meses9
Críticas18
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2021-40438 | Crítica (9) | 100% | ⚠ Explotación activa | 16 sept 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
| CVE-2020-1472 | Crítica (10) | 99% | ⚠ Explotación activa | 17 ago 2020 | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-62479 | Baja (2.7) | 0.29% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker… |
| CVE-2025-62478 | Media (4.9) | 0.33% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker… |
| CVE-2025-62477 | Media (4.9) | 0.33% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged… |
| CVE-2025-62475 | Media (4.9) | 0.33% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with… |
| CVE-2025-62289 | Media (4.9) | 0.31% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker… |
| CVE-2025-53046 | Media (4.9) | 0.41% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker… |
| CVE-2025-62480 | Baja (2.7) | 0.29% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged… |
| CVE-2025-62476 | Media (4.9) | 0.33% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged… |
| CVE-2025-62290 | Alta (7.2) | 0.35% | — | 21 oct 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker… |
| CVE-2024-21155 | Media (4.7) | 0.38% | — | 16 jul 2024 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: User Interface). The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated… |
| CVE-2024-21104 | Media (6.5) | 0.22% | — | 16 abr 2024 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with… |
| CVE-2023-21833 | Media (4.3) | 0.38% | — | 17 feb 2024 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows low privileged attacker… |
| CVE-2024-20959 | Media (4.4) | 0.18% | — | 16 ene 2024 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with… |
| CVE-2024-20914 | Baja (2.3) | 0.19% | — | 16 ene 2024 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with… |
| CVE-2022-21563 | Baja (3.4) | 0.22% | — | 19 jul 2022 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with… |
| CVE-2022-21513 | Alta (8.2) | 0.28% | — | 19 jul 2022 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with… |
| CVE-2022-29824 | Media (6.5) | 3.8% | — | 3 may 2022 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to… |
| CVE-2022-24801 | Alta (8.1) | 2.8% | — | 4 abr 2022 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request… |
| CVE-2022-23943 | Crítica (9.8) | 50% | — | 14 mar 2022 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior… |
| CVE-2022-22721 | Crítica (9.1) | 42% | — | 14 mar 2022 | If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server… |
| CVE-2022-22720 | Crítica (9.8) | 28% | — | 14 mar 2022 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling |
| CVE-2022-22719 | Alta (7.5) | 69% | — | 14 mar 2022 | A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. |
| CVE-2022-21716 | Alta (7.5) | 3.5% | — | 3 mar 2022 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version… |
| CVE-2022-23308 | Alta (7.5) | 5.1% | — | 26 feb 2022 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
| CVE-2021-4115 | Media (5.5) | 0.53% | — | 21 feb 2022 | There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process… |
| CVE-2022-25315 | Crítica (9.8) | 4.8% | — | 18 feb 2022 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. |
| CVE-2022-25314 | Alta (7.5) | 4.7% | — | 18 feb 2022 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. |
| CVE-2022-25313 | Media (6.5) | 3.3% | — | 18 feb 2022 | In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element. |
| CVE-2022-25236 | Crítica (9.8) | 34% | — | 16 feb 2022 | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. |
| CVE-2022-25235 | Crítica (9.8) | 5.0% | — | 16 feb 2022 | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.