Exploitable Vulnerability in Oracle Hospitality Cruise AffairWhere
CVE-2017-10396

9.9CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

The vulnerability in Oracle Hospitality Cruise AffairWhere could allow an attacker with low privileges, who has logged into the infrastructure where the application operates, to compromise the application. This requires some level of human interaction from a person other than the attacker. Despite being specific to the Cruise AffairWhere component, successful exploitation can also affect additional linked applications, leading to severe consequences.

Affected Version(s)

Hospitality Cruise AffairWhere 2.2.5.0

Hospitality Cruise AffairWhere 2.2.6.0

Hospitality Cruise AffairWhere 2.2.7.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.