Unauthenticated Network Vulnerability in Oracle Hospitality Reporting and Analytics
CVE-2017-10405

10CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

A network vulnerability in Oracle Hospitality Reporting and Analytics allows unauthenticated attackers to exploit the system remotely via HTTP. Attackers can gain unauthorized access to critical data and potentially compromise the integrity and availability of the application. This issue affects versions 8.5.1 and 9.0.0, with successful exploitation leading to complete access to sensitive data and the ability to cause disruptions such as system crashes or service outages, impacting overall operational efficiency.

Affected Version(s)

Hospitality Reporting and Analytics 8.5.1

Hospitality Reporting and Analytics 9.0.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.