Exploitable Vulnerability in Oracle Hospitality Cruise AffairWhere
CVE-2017-10396
9.9CRITICAL
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 October 2017
Summary
The vulnerability in Oracle Hospitality Cruise AffairWhere could allow an attacker with low privileges, who has logged into the infrastructure where the application operates, to compromise the application. This requires some level of human interaction from a person other than the attacker. Despite being specific to the Cruise AffairWhere component, successful exploitation can also affect additional linked applications, leading to severe consequences.
Affected Version(s)
Hospitality Cruise AffairWhere 2.2.5.0
Hospitality Cruise AffairWhere 2.2.6.0
Hospitality Cruise AffairWhere 2.2.7.0
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved