PT-2019-16412 · Oracle · Oracle Hospitality Reporting/Analytics

Published

2019-01-16

·

Updated

2020-08-24

·

CVE-2019-2407

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Hospitality Reporting and Analytics version 9.1.0
Description The issue allows a low-privileged attacker with Report privilege and logon access to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise the system. This can result in unauthorized access to critical data, complete access to all accessible data, as well as unauthorized update, insert, or delete access to some accessible data.
Recommendations For Oracle Hospitality Reporting and Analytics version 9.1.0, consider restricting the Report privilege to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit logon access to the infrastructure where Oracle Hospitality Reporting and Analytics executes to reduce the attack surface.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-2407

Affected Products

Oracle Hospitality Reporting/Analytics