Parsing Vulnerability in Oracle Hospitality Applications
CVE-2017-10220

4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
8 August 2017

Summary

An unauthenticated attacker with access to the infrastructure where the Hospitality Property Interfaces component executes can exploit a vulnerability in the Parser subcomponent. This security flaw allows unauthorized read access to certain data within the Hospitality Property Interfaces, potentially compromising the integrity of sensitive information.

Affected Version(s)

Hospitality Suite8 Property Interfaces 8.10.x

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.