Unauthorized Access Vulnerability in Oracle Hospitality Suite8
CVE-2020-14807
7.1HIGH
Summary
The vulnerability in Oracle Hospitality Suite8 allows an unauthenticated attacker with network access via HTTP to exploit the system. This issue requires interaction from a victim user other than the attacker, leading to unauthorized access to critical data. Successful exploitation can enable attackers to perform unauthorized actions such as updating, inserting, or deleting accessible data within the Oracle Hospitality Suite8 environment. This presents significant risks concerning data confidentiality and integrity.
Affected Version(s)
Hospitality Suite8 8.10.2
Hospitality Suite8 8.11-8.14
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved