First published: Tue Aug 08 2017(Updated: )
Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Hospitality Property Interfaces executes to compromise Hospitality Property Interfaces. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hospitality Property Interfaces accessible data. CVSS 3.0 Base Score 4.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Hospitality Suite 8 Property Interfaces | =8.10.0 | |
Oracle Hospitality Suite 8 Property Interfaces | =8.10.1 | |
Oracle Hospitality Suite 8 Property Interfaces | =8.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10220 is classified as a high-severity vulnerability due to its ease of exploitation by unauthenticated attackers.
To remediate CVE-2017-10220, it is essential to apply the latest security patches provided by Oracle for affected versions of Hospitality Property Interfaces.
CVE-2017-10220 impacts Oracle Hospitality Suite 8 Property Interfaces versions 8.10.0, 8.10.1, and 8.10.2.
If exploited, CVE-2017-10220 could allow attackers to gain unauthorized access to sensitive information within the hospitality application's infrastructure.
Organizations using Oracle Hospitality Suite 8 Property Interfaces versions 8.10.x are at risk for CVE-2017-10220.