PT-2019-16412 · Oracle · Oracle Hospitality Reporting/Analytics

Publicado

2019-01-16

·

Atualizado

2020-08-24

·

CVE-2019-2407

CVSS v3.1

6.1

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Hospitality Reporting and Analytics version 9.1.0
Description The issue allows a low-privileged attacker with Report privilege and logon access to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise the system. This can result in unauthorized access to critical data, complete access to all accessible data, as well as unauthorized update, insert, or delete access to some accessible data.
Recommendations For Oracle Hospitality Reporting and Analytics version 9.1.0, consider restricting the Report privilege to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit logon access to the infrastructure where Oracle Hospitality Reporting and Analytics executes to reduce the attack surface.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-2407

Produtos afetados

Oracle Hospitality Reporting/Analytics