Vulnerability in Oracle Hospitality Suites Management Component
CVE-2017-10079

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
8 August 2017

Summary

A vulnerability exists in the Oracle Hospitality Suites Management component of Oracle Hospitality Applications, specifically in version 3.7. This flaw can be exploited by an unauthenticated attacker with network access via HTTP, leading to significant security implications. Although the compromised system requires human interaction from a third party, successful exploitation can grant unauthorized capabilities to update, insert, or delete data available within the Oracle Hospitality Suites Management interface. Additionally, attackers may gain unauthorized read access to a portion of the accessible data, posing a serious threat to information integrity and confidentiality across impacted products.

Affected Version(s)

Hospitality Suites Management 3.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.