SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-10224

Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Inventory and Count Cycle).

MEDIUM 6.4EPSS 1.15%

Does this matter?

Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.

Description

Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Inventory and Count Cycle). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Inventory Management. While the vulnerability is in Oracle Hospitality Inventory Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Inventory Management accessible data as well as unauthorized read access to a subset of Oracle Hospitality Inventory Management accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).

CVSS 3.0
6.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
EPSS
1.15% probability · 65th percentile
CISA KEV
Not listed
Affected
oracle/hospitality inventory management
Source
secalert_us@oracle.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.