EXPOSURES › CVE-2019-3010
CVE-2019-3010
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Solaris XScreenSaver privilege escalation vulnerability was actively exploited in the wild.
An unspecified vulnerability in Oracle Solaris XScreenSaver allowed attackers to escalate privileges, and it was listed in CISA's KEV catalog indicating active exploitation. DIB organizations must ensure all Oracle Solaris systems are patched immediately to prevent unauthorized access and maintain compliance with security requirements.
Shame score — The vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating significant risk and avoidable exposure due to lack of timely patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |