CVE-2017-10218: Medium severity oracle hospitality guest access vulnerability
Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10218?
CVE-2017-10218 is rated as a high severity vulnerability due to its ease of exploitation by low privileged attackers.
How do I fix CVE-2017-10218?
To fix CVE-2017-10218, update Oracle Hospitality Guest Access to version 4.2.2.0 or later.
What are the affected versions in CVE-2017-10218?
The affected versions for CVE-2017-10218 are 4.2.0.0 and 4.2.1.0 of Oracle Hospitality Guest Access.
Can CVE-2017-10218 be exploited remotely?
Yes, CVE-2017-10218 can be exploited remotely with network access via HTTP.
Who is at risk from CVE-2017-10218?
Organizations using affected versions of Oracle Hospitality Guest Access are at risk from CVE-2017-10218.