Denial of Service Vulnerability in Oracle Hospitality Cruise Fleet Management
CVE-2017-10399
3.1LOW
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 October 2017
Summary
This vulnerability affects the Oracle Hospitality Cruise Fleet Management component, allowing a low-privileged attacker with network access via HTTP to potentially disrupt service. Exploitation of this flaw can lead to unauthorized partial denial of service, impacting the availability of the application. The issue is linked to the GangwayActivityWebApp subcomponent, and while the risk is mitigated for users with protective measures, organizations utilizing version 9.0.2.0 should take proactive steps to secure their systems.
Affected Version(s)
Hospitality Cruise Fleet Management 9.0.2.0
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved