Vulnerability in Oracle Retail Xstore Point of Service Affects Multiple Versions
CVE-2017-10183

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
8 August 2017

Summary

This vulnerability in the Oracle Retail Xstore Point of Service enables unauthenticated attackers with network access via HTTP to potentially compromise sensitive data. Attackers could exploit this vulnerability, leading to unauthorized updates, insertions, or deletions within Oracle Retail Xstore's accessible data. The vulnerability also allows for unauthorized reading of certain data and has the potential to cause partial denial of service incidents, impacting the functionality of the service.

Affected Version(s)

Retail Xstore Point of Service 6.0.x

Retail Xstore Point of Service 6.5.x

Retail Xstore Point of Service 7.0.x

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.