Denial of Service Vulnerability in Oracle Hospitality Cruise Fleet Management
CVE-2017-10399

3.1LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

This vulnerability affects the Oracle Hospitality Cruise Fleet Management component, allowing a low-privileged attacker with network access via HTTP to potentially disrupt service. Exploitation of this flaw can lead to unauthorized partial denial of service, impacting the availability of the application. The issue is linked to the GangwayActivityWebApp subcomponent, and while the risk is mitigated for users with protective measures, organizations utilizing version 9.0.2.0 should take proactive steps to secure their systems.

Affected Version(s)

Hospitality Cruise Fleet Management 9.0.2.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.