Oracle ZFS Storage Appliance: ZS3-2 - NTP server version disclosure after ILOM upgrade to 188.8.131.52 r117708
(Doc ID 2384548.1)
Last updated on JULY 24, 2018
Applies to:Oracle ZFS Storage ZS3-2 - Version All Versions and later
7000 Appliance OS (Fishworks)
After upgrading the ZS3-2 ILOM/BIOS version to 184.108.40.206 r117708 we are able to obtain sensitive information from our ZS3-2 SP.
Nessus elicited the following response from the remote host by sending an NTP mode 6 query :
Version details of the ZS3-2:
Appliance Kit ak/SUNW,maguroG2@2013.06.05.7.14,1-1.1
Operating System SunOS 5.11 email@example.com,1-1.1 64-bit
BIOS American Megatrends Inc. 21000227 03/11/2016
Service Processor 220.127.116.11 r117708
After upgrading the ILOM/BIOS version to 18.104.22.168 r117708
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!