Skip to content
COOEY

EXPOSURES › CVE-2020-14871

CVE-2020-14871

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-14871 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatched

An unspecified vulnerability in Oracle Solaris and ZFS was actively exploited in the wild, causing high impacts to confidentiality, integrity, and availability.

Oracle Solaris and ZFS Storage Appliance Kit contained an unspecified vulnerability that was added to CISA's KEV catalog, indicating active exploitation. DIB organizations must ensure their Oracle Solaris and ZFS systems are patched immediately to prevent potential data breaches, system compromise, or service disruption. The lack of specific technical details in the source limits the ability to assess RCE or zero-day status, but the KEV designation alone warrants urgent patching.

Shame score — The vulnerability was actively exploited in the wild and added to CISA's KEV catalog, demonstrating a failure to patch a known or exploitable issue before adversaries leveraged it for high-impact attacks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

SENTIMENT · TRUSTED SOURCES
synthesis neutral -0.20
No direct sentiment expressed; sources are technical databases or vendor pages without commentary on Oracle's handling.
cooey ↗ neutral +0.00
Neutral technical description; no sentiment toward Oracle's handling.
"Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems."
cvedb.shodan.io ↗ neutral +0.00
Neutral API dashboard; no sentiment expressed.
"CVEDB API - Fast Vulnerability Dashboard - Shodan"
www.cvefind.com ↗ neutral +0.00
Neutral database; no sentiment expressed.
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
xposedornot.com ↗ neutral +0.00
Neutral breach directory; no sentiment expressed.
"Data Breach Directory & Database: Browse 760+ Known Breaches - XposedOrNot"
CISA ↗ neutral +0.00
Neutral government site; no sentiment expressed.
"ICS Advisories | CISA"
www.oracle.com ↗ neutral +0.00
Neutral vendor page; no sentiment expressed.
"Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins"
AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized