First published: Tue Aug 08 2017(Updated: )
Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Hospitality Guest Access | =4.2.0.0 | |
Oracle Hospitality Guest Access | =4.2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10218 is rated as a high severity vulnerability due to its ease of exploitation by low privileged attackers.
To fix CVE-2017-10218, update Oracle Hospitality Guest Access to version 4.2.2.0 or later.
The affected versions for CVE-2017-10218 are 4.2.0.0 and 4.2.1.0 of Oracle Hospitality Guest Access.
Yes, CVE-2017-10218 can be exploited remotely with network access via HTTP.
Organizations using affected versions of Oracle Hospitality Guest Access are at risk from CVE-2017-10218.