Vulnerability in Oracle Hospitality Applications' Cloud Service Components
CVE-2017-10064
6.1MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 8 August 2017
Summary
A vulnerability exists in Oracle's Hospitality WebSuite8 Cloud Service, allowing unauthenticated attackers with network access via HTTP to potentially compromise sensitive data. This vulnerability affects versions 8.9.6 and 8.10.x, permitting unauthorized users to gain access to modify, delete, or retrieve data after human interaction from an unconnected user. The attacks could not only compromise the Hospitality WebSuite8 Cloud Service but also impact other connected products, leading to possible data integrity and confidentiality breaches.
Affected Version(s)
Hospitality WebSuite8 Cloud Service 8.9.6
Hospitality WebSuite8 Cloud Service 8.10.x
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved