PT-2018-16050 · Oracle · Oracle Hospitality Cruise Fleet Management

Published

2018-10-17

·

Updated

2019-10-03

·

CVE-2018-3166

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Oracle Hospitality Cruise Fleet Management version 9.0
Description The issue allows a low-privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Fleet Management, resulting in unauthorized creation, deletion, or modification access to critical data or all accessible data.
Recommendations For version 9.0, update to a version that includes a fix for this issue, however, at the moment, there is no information about a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the Emergency Response System component to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-3166

Affected Products

Oracle Hospitality Cruise Fleet Management