SQL Injection Vulnerability in Oracle Hospitality Applications
CVE-2019-2409

6.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2019

Summary

A vulnerability exists in the Oracle Hospitality Cruise Shipboard Property Management System component, which could allow an attacker with low privileges to compromise the system. To exploit this vulnerability, the attacker requires access to the infrastructure where the system operates and must prompt human interaction from a third party. The exploitation may lead to unauthorized capabilities such as causing system disruptions, including Denial of Service (DOS), and gaining unauthorized access to sensitive data. This vulnerability could significantly impact not only the Cruise Shipboard Property Management System but also other connected applications within the ecosystem.

Affected Version(s)

Hospitality Cruise Shipboard Property Management System 8.0.8

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.