Learn about CVE-2017-10395 affecting Oracle Hospitality Cruise Fleet Management version 9.0.2.0. This vulnerability allows unauthorized data access and manipulation. Find mitigation steps here.
Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications has a vulnerability that affects version 9.0.2.0. This CVE was published on October 19, 2017.
Understanding CVE-2017-10395
This CVE involves an easily exploitable vulnerability in the GangwayActivityWebApp subcomponent of Oracle Hospitality Cruise Fleet Management.
What is CVE-2017-10395?
The vulnerability allows a low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Fleet Management. Unauthorized actions like update, insert, or delete access to certain data may occur, along with unauthorized read access to a portion of the data.
The Impact of CVE-2017-10395
The vulnerability has a CVSS 3.0 Base Score of 5.4, impacting confidentiality and integrity. Successful exploitation could lead to unauthorized data access and manipulation.
Technical Details of CVE-2017-10395
This section provides more technical insights into the vulnerability.
Vulnerability Description
The vulnerability in Oracle Hospitality Cruise Fleet Management allows unauthorized data access and manipulation by a low privileged attacker via HTTP.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by a low privileged attacker with network access through HTTP, enabling unauthorized data access and manipulation.
Mitigation and Prevention
It is crucial to take immediate steps to address and prevent exploitation of this vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates