Authentication Bypass in Oracle Hospitality Reporting and Analytics
CVE-2018-2650

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A vulnerability exists in the Oracle Hospitality Reporting and Analytics component, which might allow a low-privileged attacker with network access via HTTP to compromise the system. This exploitable weakness can lead to unauthorized actions, including creation, deletion, or modification of critical data within the Oracle Hospitality Reporting and Analytics environment. Additionally, it may permit unauthorized read access to specific datasets, exposing sensitive information linked to the reporting and analytics capabilities.

Affected Version(s)

Hospitality Reporting and Analytics 8.5.1

Hospitality Reporting and Analytics 9.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.