First published: Thu Apr 19 2018(Updated: )
Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Profile). The supported version that is affected is 8.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Suite8 accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Suite8 accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Suite8. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Hospitality Suite8 | >=8.9.0<=8.9.6.30 | |
Oracle Hospitality Suite8 | =8.10.0 | |
Oracle Hospitality Suite8 | =8.10.1 | |
Oracle Hospitality Suite8 | =8.10.2 | |
Oracle Hospitality Suite8 | =8.11.0.0 | |
Oracle Hospitality Suite8 | =8.12.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2827 is a vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications.
CVE-2018-2827 has a severity value of 7.6, which is classified as high.
Oracle Hospitality Suite8 versions 8.0 to 8.9.6.30, 8.10.0, 8.10.1, 8.10.2, 8.11.0.0, and 8.12.0.0 are affected by CVE-2018-2827.
A low privileged attacker with network access via HTTP can exploit CVE-2018-2827 to compromise Oracle Hospitality Suite8.
You can find more information about CVE-2018-2827 on the Oracle Security Advisory website (Link: http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html) and the SecurityFocus website (Link: http://www.securityfocus.com/bid/103914).