Skip to content
COOEY

EXPOSURES › CVE-2019-3010

CVE-2019-3010

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-3010 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatched

Oracle Solaris XScreenSaver privilege escalation vulnerability was actively exploited in the wild.

An unspecified vulnerability in Oracle Solaris XScreenSaver allowed attackers to escalate privileges, and it was listed in CISA's KEV catalog indicating active exploitation. DIB organizations must ensure all Oracle Solaris systems are patched immediately to prevent unauthorized access and maintain compliance with security requirements.

Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating significant risk and avoidable exposure due to lack of timely patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized