Vulnerability in Oracle Retail Xstore Point of Service Affecting Multiple Versions
CVE-2017-10427

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

A vulnerability exists in the Oracle Retail Xstore Point of Service, affecting specific supported versions. This issue allows unauthenticated attackers with network access via HTTP to potentially exploit the system. Such exploits can result in unauthorized modifications, including updates, inserts, and deletions of accessible data, along with unauthorized reading of a subset of data. Additionally, attackers may generate conditions for a partial denial of service against the Oracle Retail Xstore Point of Service, impacting its availability and reliability.

Affected Version(s)

Retail Xstore Point of Service 6.0.11

Retail Xstore Point of Service 6.5.11

Retail Xstore Point of Service 7.0.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.