First published: Thu Oct 19 2017(Updated: )
Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Interface). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Guest Access accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Hospitality Guest Access | =4.2.0 | |
Oracle Hospitality Guest Access | =4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10383 is considered a critical vulnerability due to its ease of exploitation and potential impact on Oracle Hospitality Guest Access.
To fix CVE-2017-10383, update your Oracle Hospitality Guest Access software to the latest version available.
CVE-2017-10383 affects Oracle Hospitality Guest Access versions 4.2.0 and 4.2.1.
Yes, CVE-2017-10383 can be exploited remotely by an unauthenticated attacker with network access via HTTP.
CVE-2017-10383 is an easily exploitable vulnerability that compromises the Oracle Hospitality Guest Access interface.