CVE-2018-2607
published 2018-01-18CVE-2018-2607: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). The supported version that is affected…
PriorityP419medium4.9CVSS 3.0
AVNACLPRHUINSUCNINAH
EPSS
1.12%
62.4th percentile
Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). The supported version that is affected is 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Guest Access. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | hospitality_guest_access | — | — |
| oracle_corporation | hospitality_guest_access | — | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10914 glusterfs: remote denial of service of gluster volumes via posix_get_file_contents function in posix-helpers.c
bugzilla·2018-07-23·CVSS 6.5
CVE-2018-10914 [MEDIUM] CVE-2018-10914 glusterfs: remote denial of service of gluster volumes via posix_get_file_contents function in posix-helpers.c
CVE-2018-10914 glusterfs: remote denial of service of gluster volumes via posix_get_file_contents function in posix-helpers.c
A flaw was found in GlusterFS. A NULL pointer dereference vulnerability due to an improper implementation of the posix_get_file_contents function. An attacker could exploit this to perform a Denial of Service attack.
Discussion:
Acknowledgments:
Name: Michael Hanselmann (hansmi.ch)
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.4 for RHEL 7
Native Client for RHEL 7 for Red Hat Storage
Via RHSA-2018:2607 https://access.redhat.com/errata/RHSA-2018:2607
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.4 for RHEL 6
Native Client for RHEL 6 for Red Hat Storage
Via RHSA-2018:2608 htt
Bugzilla
CVE-2018-10913 glusterfs: Information Exposure in posix_get_file_contents function in posix-helpers.c
bugzilla·2018-07-23·CVSS 6.5
CVE-2018-10913 [MEDIUM] CVE-2018-10913 glusterfs: Information Exposure in posix_get_file_contents function in posix-helpers.c
CVE-2018-10913 glusterfs: Information Exposure in posix_get_file_contents function in posix-helpers.c
A flaw was found in GlusterFS. An Information Exposure vulnerability due to an improper implementation of the glusterfs.file function. An attacker could exploit this to obtain information about the files available.
Discussion:
Acknowledgments:
Name: Michael Hanselmann (hansmi.ch)
---
Created glusterfs tracking bugs for this issue:
Affects: fedora-all [bug 1625074]
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.4 for RHEL 7
Native Client for RHEL 7 for Red Hat Storage
Via RHSA-2018:2607 https://access.redhat.com/errata/RHSA-2018:2607
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.4 for RHEL 6
Nativ
2018-01-18
Published