Vulnerability in Oracle Hospitality Applications' Cloud Service Components
CVE-2017-10064

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
8 August 2017

Summary

A vulnerability exists in Oracle's Hospitality WebSuite8 Cloud Service, allowing unauthenticated attackers with network access via HTTP to potentially compromise sensitive data. This vulnerability affects versions 8.9.6 and 8.10.x, permitting unauthorized users to gain access to modify, delete, or retrieve data after human interaction from an unconnected user. The attacks could not only compromise the Hospitality WebSuite8 Cloud Service but also impact other connected products, leading to possible data integrity and confidentiality breaches.

Affected Version(s)

Hospitality WebSuite8 Cloud Service 8.9.6

Hospitality WebSuite8 Cloud Service 8.10.x

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.