First published: Thu Oct 19 2017(Updated: )
Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Hospitality Suite8 | =8.10.1 | |
Oracle Hospitality Suite8 | =8.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10318 has been classified as a high severity vulnerability due to its easily exploitable nature.
To fix CVE-2017-10318, update to a patched version of Oracle Hospitality Suite8, specifically versions 8.10.3 or later.
CVE-2017-10318 affects users of Oracle Hospitality Suite8 running versions 8.10.1 and 8.10.2.
CVE-2017-10318 allows an unauthenticated attacker with network access to compromise Oracle Hospitality Suite8 via HTTP.
CVE-2017-10318 was disclosed in October 2017 as part of Oracle's Critical Patch Update.