Vulnerability in Oracle Hospitality Hotel Mobile Affects Suite8 REST API
CVE-2017-10353

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

The vulnerability in Oracle Hospitality Hotel Mobile, specifically within the Suite8 REST API, allows an attacker with low privileges and network access via HTTP to exploit this security loophole. Successful exploitation could lead to unauthorized access to sensitive data, granting the attacker complete access to all data within the application. Additionally, this vulnerability may permit the attacker to cause a partial denial of service, impacting the availability of the application. Organizations utilizing affected versions must implement mitigations to safeguard against potential exploitations.

Affected Version(s)

Hospitality Hotel Mobile 1.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.