PT-2020-4550 · Oracle · Oracle Hospitality Res 3700
Walid Faour
·
Published
2020-10-21
·
Updated
2020-10-26
·
CVE-2020-14783
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Hospitality RES 3700 version 5.7
Description
The issue is related to insufficient input validation in the CAL component of Oracle Hospitality RES 3700, allowing an unauthenticated attacker with network access via TCP to compromise the system. Successful attacks can result in unauthorized read access to a subset of Oracle Hospitality RES 3700 accessible data.
Recommendations
For Oracle Hospitality RES 3700 version 5.7, apply the necessary security patches or updates to fix the insufficient input validation issue in the CAL component. As a temporary workaround, consider restricting network access via TCP to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Hospitality Res 3700