Sun Microsystems, Inc.  Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-71-2279824.1
Update Date:2017-06-23
Keywords:

Solution Type  Technical Instruction Sure

Solution  2279824.1 :   Oracle Security Alert for CVE-2017-3629 versus the VLE, VSM6 or VSM7  


Related Items
  • StorageTek Virtual Storage Manager System 6 (VSM6)
  •  
  • Sun Virtual Library Extension (VLE)
  •  
  • StorageTek Virtual Storage Manager System 7 (VSM7)
  •  
Related Categories
  • PLA-Support>Sun Systems>TAPE>Virtual Tape>SN-TP: VLE
  •  




In this Document
Goal
Solution
References


Applies to:

Sun Virtual Library Extension (VLE) - Version 1.0 to 1.5 [Release 1.0]
StorageTek Virtual Storage Manager System 6 (VSM6) - Version All Versions to All Versions [Release All Releases]
StorageTek Virtual Storage Manager System 7 (VSM7) - Version 7.0.0 to 7.1.1 [Release 7.0]
Information in this document applies to any platform.

Goal

 Does Oracle Security Alert for CVE-2017-3629 apply to the VLE, VSM6 or VSM7?

 Please note that information on the Oracle Security Alert for CVE-2017-3629 can also be found in MOS Doc ID 2277900.1.

Solution

 To exploit this vulnerability, the user must first login to a node on the VLE or VSM system.  It is not a network based vulnerability.

 The VLE and VSM systems are currently maintained by Oracle Field Engineers who have login credentials to the system and they also have privileged access to the system.

 Engineering management for the VLE, VSM6 and VSM7 has therefore determined there is not an additional exposure to the VLE or VSM products based on this CVE.


Attachments
This solution has no attachment
  Copyright © 2018 Oracle, Inc.  All rights reserved.
 Feedback