PT-2020-2384 · Oracle · Oracle Hospitality Reporting/Analytics

Published

2020-04-15

·

Updated

2020-04-15

·

CVE-2020-2746

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Oracle Hospitality Reporting and Analytics version 9.1.0
Description The issue is related to a lack of protection for service data in the Oracle Hospitality Reporting and Analytics component. This can be exploited by a remote attacker using HTTP requests, potentially affecting the confidentiality and integrity of protected information. Successful attacks can result in unauthorized access to critical data, including creation, deletion, or modification of data.
Recommendations For version 9.1.0, update to a newer version that addresses this issue to prevent unauthorized access and modifications to critical data. As a temporary workaround, consider restricting access to the Oracle Hospitality Reporting and Analytics component via HTTP to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02352
CVE-2020-2746

Affected Products

Oracle Hospitality Reporting/Analytics