CVE-2017-10195

5 documents5 sources
Severity
4.3MEDIUM
EPSS
1.1%
top 22.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateMay 13

Description

Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export). The supported version that is affected is 2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6396-hjp5-8hhx: Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export)2022-05-13
CVEList
CVE-2017-10195: Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Export)2017-08-08

📋Vendor Advisories

1
Red Hat
Mozilla: Vulnerabilities in libevent library (MFSA 2017-11, MFSA 2017-12)2017-04-19

💬Community

1
Bugzilla
CVE-2016-10195 libevent: Stack-buffer overflow in the name_parse() function2017-02-02
CVE-2017-10195 (MEDIUM CVSS 4.3) | Vulnerability in the Oracle Hospita | cvebase.io