Security Vulnerability in Hospitality WebSuite8 Cloud Service by Oracle
CVE-2017-10128

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
8 August 2017

Summary

The Hospitality WebSuite8 Cloud Service by Oracle contains a vulnerability that allows unauthenticated attackers to exploit the service through network access via HTTP. The affected versions, 8.9.6 and 8.10.x, can be targeted to gain unauthorized access to the service. Successful exploitation of this vulnerability necessitates human interaction from an unsuspecting user, leading to the potential for unauthorized updates, inserts, or deletions of accessible data, as well as unauthorized reading of sensitive information. While the vulnerability primarily affects Hospitality WebSuite8, its implications may extend to other interconnected products within Oracle's hospitality applications.

Affected Version(s)

Hospitality WebSuite8 Cloud Service 8.9.6

Hospitality WebSuite8 Cloud Service 8.10.x

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.