Oracle Solaris 9
Oracle Solaris 9
The Oracle OS Oracle Solaris 9 reached end of service life on Oct 1, 2014 — Oracle OS no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Oracle Solaris 9 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- oracle-solaris
- release
- 9
- product Label
- Oracle Solaris
- release Label
- 9
- codename
- lts
- latest Version
- release Date
- 2002-05-28
- maintained
- source Url
- https://endoflife.date/oracle-solaris
Lifecycle Dates
- End of Service Life
- Oct 1, 2014
- Last OEM Support
- Oct 1, 2011
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Oracle Solaris 9 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Oracle Solaris 9?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Oracle Solaris 9 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Oracle Solaris 9 Support: Frequently Asked Questions
Is the Oracle OS Oracle Solaris 9 still supported?
Oracle OS ended support for the Oracle Solaris 9 on Oct 1, 2014 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Oracle OS Oracle Solaris 9 end of service life (EOSL) date?
Oracle OS lists the end of service life for the Oracle Solaris 9 as Oct 1, 2014.
Can I keep using the Oracle Solaris 9 after its EOSL date?
Yes. EOSL means Oracle OS stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Oracle Solaris 9 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Oracle Solaris 9
24 published CVEs affect the Oracle OS Oracle Solaris 9, including 8 rated critical or high severity. Oracle OS no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2020-14871 | CRITICAL | 10.0 | Oct 21, 2020 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: This CVE is n |
| CVE-2017-3623 | CRITICAL | 10.0 | Apr 24, 2017 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see note. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. While the vulnerability is in Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Solaris. Note: CVE-2017-3623 is assigned for "Ebbisl |
| CVE-2010-3509 | HIGH | 10.0 | Oct 14, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scheduler. |
| CVE-2002-1337 | HIGH | 10.0 | Mar 7, 2003 | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c. |
| CVE-1999-0046 | HIGH | 10.0 | Feb 6, 1997 | Buffer overflow of rlogin program using TERM environmental variable. |
| CVE-2016-2334 | HIGH | 7.8 | Dec 13, 2016 | Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image. |
| CVE-2011-3537 | HIGH | 7.8 | Oct 18, 2011 | Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel/Filesystem. |
| CVE-2008-4609 | HIGH | 7.1 | Oct 20, 2008 | The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress. |
| CVE-2010-3507 | MEDIUM | 6.6 | Oct 14, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Live Upgrade. |
| CVE-2009-2857 | MEDIUM | 5.5 | Aug 19, 2009 | The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file. |
| CVE-2011-3534 | MEDIUM | 5.0 | Oct 18, 2011 | Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network Status Monitor (statd). |
| CVE-2010-2386 | MEDIUM | 4.9 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect availability via unknown vectors related to GigaSwift Ethernet Driver. |
| CVE-2009-3519 | MEDIUM | 4.9 | Oct 1, 2009 | Multiple memory leaks in the IP module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_109, allow local users to cause a denial of service (memory consumption) via vectors related to (1) M_DATA, (2) M_PROTO, (3) M_PCPROTO, and (4) M_SIG STREAMS messages. |
| CVE-2010-2400 | MEDIUM | 4.6 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 9 and 10, and OpenSolaris, allows local users to affect availability via unknown vectors related to Kernel/Filesystem. |
| CVE-2010-3515 | MEDIUM | 4.0 | Oct 14, 2010 | Unspecified vulnerability in the Solaris component in Oracle Solaris 9 and 10, and OpenSolaris, allows local users to affect availability via unknown vectors related to Kernel/Disk Driver. |
| CVE-1999-0524 | MEDIUM | 4.0 | Aug 1, 1997 | ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. |
| CVE-2010-3576 | LOW | 3.6 | Oct 14, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect integrity and availability, related to the SCSI enclosure services device driver. |
| CVE-2010-2384 | LOW | 3.2 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality and integrity via unknown vectors related to Solaris Management Console. |
| CVE-2010-2383 | LOW | 3.2 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality and integrity, related to NFS. |
| CVE-2010-2382 | LOW | 3.2 | Jul 13, 2010 | Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors. |
Showing the 20 most severe of 24 known CVEs.
Get Third Party Support