Parsing Vulnerability in Oracle Hospitality Applications
CVE-2017-10220
4MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 8 August 2017
Summary
An unauthenticated attacker with access to the infrastructure where the Hospitality Property Interfaces component executes can exploit a vulnerability in the Parser subcomponent. This security flaw allows unauthorized read access to certain data within the Hospitality Property Interfaces, potentially compromising the integrity of sensitive information.
Affected Version(s)
Hospitality Suite8 Property Interfaces 8.10.x
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved