Vulnerability in Oracle Hospitality Simphony First Edition Component
CVE-2017-10001
7.6HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 8 August 2017
Summary
An exploitable flaw exists in Oracle Hospitality Simphony First Edition within the Core component, specifically in version 1.7.1. This vulnerability permits a low-privileged attacker with network access via HTTP to compromise the system, requiring human interaction from a third party to successfully execute an attack. When exploited, this vulnerability can lead to unauthorized access to critical data, allowing the attacker to manipulate data through insert, update, or delete operations. It also opens up risks for denial-of-service conditions, including crashing the application. Proper security measures must be taken to safeguard against potential exploits.
Affected Version(s)
Hospitality Simphony First Edition 1.7.1
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved