Unauthorized Access Vulnerability in Oracle Hospitality Suite8
CVE-2020-14807

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 October 2020

Summary

The vulnerability in Oracle Hospitality Suite8 allows an unauthenticated attacker with network access via HTTP to exploit the system. This issue requires interaction from a victim user other than the attacker, leading to unauthorized access to critical data. Successful exploitation can enable attackers to perform unauthorized actions such as updating, inserting, or deleting accessible data within the Oracle Hospitality Suite8 environment. This presents significant risks concerning data confidentiality and integrity.

Affected Version(s)

Hospitality Suite8 8.10.2

Hospitality Suite8 8.11-8.14

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.