CVE-2018-2669: Medium severity oracle hospitality reporting and analytics vulnerability
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Report). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized read access to a subset of Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability CVE-2018-2669?
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications, allowing an unauthenticated attacker to compromise the system.
How can an attacker exploit CVE-2018-2669?
By using network access via HTTP, an attacker can exploit the vulnerability in the Oracle Hospitality Reporting and Analytics component.
What versions of Oracle Hospitality Reporting and Analytics are affected by CVE-2018-2669?
Versions 8.5.1 and 9.0.0 of Oracle Hospitality Reporting and Analytics are affected by the vulnerability.
What is the severity of CVE-2018-2669?
The severity of CVE-2018-2669 is medium with a CVSS score of 6.1.
Is there a fix for CVE-2018-2669?
Yes, Oracle has released patches and updates to address the vulnerability. It is recommended to update to the latest version of Oracle Hospitality Applications.