Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Interface). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
References
Link | Resource |
---|---|
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/101436 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-10-19 10:29
Updated : 2017-10-22 18:29
NVD link : CVE-2017-10383
Mitre link : CVE-2017-10383
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
oracle
- hospitality_guest_access