PatchSiren cyber security CVE debrief
CVE-2019-3010 Oracle CVE debrief
CVE-2019-3010 is an Oracle Solaris privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-05-25. That KEV listing is the key signal here: it indicates the issue has been observed as exploited and should be treated as a high-priority remediation item. The supplied corpus does not include CVSS scoring, so operational urgency should be driven by the KEV status and vendor guidance rather than a score.
- Vendor
- Oracle
- Product
- Solaris
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-05-25
- Original CVE updated
- 2022-05-25
- Advisory published
- 2022-05-25
- Advisory updated
- 2022-05-25
Who should care
Administrators and security teams responsible for Oracle Solaris systems should care most, especially anyone tracking remediation against CISA KEV requirements or managing externally reachable, production, or privileged Solaris hosts.
Technical summary
The supplied sources identify CVE-2019-3010 as an Oracle Solaris privilege escalation vulnerability. CISA’s KEV catalog lists it as known exploited and directs defenders to apply updates per vendor instructions. No additional technical details, attack path, or CVSS data are included in the supplied corpus.
Defensive priority
High. CISA KEV inclusion makes this a time-sensitive remediation item, and the KEV entry includes a due date of 2022-06-15 for applying updates per vendor instructions.
Recommended defensive actions
- Identify all Oracle Solaris systems in your environment.
- Check whether Oracle has issued updates or mitigation guidance for CVE-2019-3010 and apply them per vendor instructions.
- Prioritize internet-facing, production, and high-privilege Solaris systems for remediation.
- Confirm patch deployment and verify affected hosts are no longer outstanding against KEV-based remediation tracking.
- Monitor Oracle and CISA references for any additional guidance or updates related to this CVE.
Evidence notes
Primary evidence comes from CISA’s Known Exploited Vulnerabilities feed, which lists vendorProject Oracle, product Solaris, vulnerabilityName “Oracle Solaris Privilege Escalation Vulnerability,” dateAdded 2022-05-25, dueDate 2022-06-15, and requiredAction “Apply updates per vendor instructions.” The supplied record also points to the NVD detail page for CVE-2019-3010 and the CVE.org record as official references. No CVSS score or deeper technical exploit details were provided in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-3010 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-3010
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-3010 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-3010
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.