Vulnerability in Oracle Hospitality Inventory Management Affects Multiple Versions
CVE-2017-10224
6.4MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 8 August 2017
Summary
This vulnerability in the Oracle Hospitality Inventory Management component allows attackers with low privileges and network access via HTTP to exploit the system. It poses a risk as it enables unauthorized update, insert, or delete operations on sensitive data, and allows unauthorized reading of accessible data. Attackers can exploit this weakness to gain significant control over the Inventory Management functions, which may also affect other interconnected products.
Affected Version(s)
Hospitality Inventory Management 8.5.1
Hospitality Inventory Management 9.0.0
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved