CVE-2018-3000Uncontrolled Resource Consumption in Corporation Hospitality Cruise Shipboard Property Management System

Severity
7.1HIGHNVD
EPSS
0.2%
top 52.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMar 7

Description

Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Cruise Shipboard Property Management System executes to compromise Oracle Hospitality Cruise Shipboard Property Management System. While the vulnerability is in Oracle Hospi

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NExploitability: 2.5 | Impact: 4.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5fvc-ffgp-mm9h: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS S2022-05-13
GHSA
Craft CMS PHP Code Injection Vulnerability2022-05-13
CVEList
CVE-2018-3000: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS S2018-07-18

💥Exploits & PoCs

5
Exploit-DB
Saltstack 3000.1 - Remote Code Execution2020-05-05
Exploit-DB
Cisco Adaptive Security Appliance - Path Traversal (Metasploit)2019-08-12
Exploit-DB
Cisco Adaptive Security Appliance - Path Traversal2018-06-28
Exploit-DB
antMan 0.9.0c - Authentication Bypass2018-03-07
Exploit-DB
antMan < 0.9.1a - Authentication Bypass2018-03-02

📋Vendor Advisories

3
Chrome
Stable Channel Update for Desktop: CVE-2023-12312023-03-07
Chrome
Stable Channel Update for Desktop: CVE-2021-305582021-05-25
Cisco
Cisco Nexus 3000 and 9000 Series CLI and Simple Network Management Protocol Polling Denial of Service Vulnerability2018-06-20
CVE-2018-3000 — Uncontrolled Resource Consumption | cvebase