Information Disclosure and Data Manipulation Vulnerability in Oracle Hospitality Applications
CVE-2017-10223

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
8 August 2017

What is CVE-2017-10223?

The vulnerability in Oracle Hospitality Materials Control enables a low privileged attacker with network access via HTTP to compromise the system. Exploitation of this flaw may result in unauthorized updates, inserts, or deletions of accessible data, alongside unauthorized read access to some data within Oracle Hospitality Materials Control. The issue primarily affects versions 8.31.4 and 8.32.0, posing risks to data integrity and confidentiality. Organizations using these affected versions should consider immediate remediation measures.

Affected Version(s)

Hospitality Materials Control 8.31.4

Hospitality Materials Control 8.32.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-10223 : Information Disclosure and Data Manipulation Vulnerability in Oracle Hospitality Applications