PT-2019-16412 · Oracle · Oracle Hospitality Reporting/Analytics
Published
2019-01-16
·
Updated
2020-08-24
·
CVE-2019-2407
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Hospitality Reporting and Analytics version 9.1.0
Description
The issue allows a low-privileged attacker with Report privilege and logon access to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise the system. This can result in unauthorized access to critical data, complete access to all accessible data, as well as unauthorized update, insert, or delete access to some accessible data.
Recommendations
For Oracle Hospitality Reporting and Analytics version 9.1.0, consider restricting the Report privilege to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit logon access to the infrastructure where Oracle Hospitality Reporting and Analytics executes to reduce the attack surface.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Hospitality Reporting/Analytics