CVE-2019-2410Corporation Hospitality Cruise Shipboard Property Management System vulnerability

4 documents4 sources
Severity
5.1MEDIUMNVD
EPSS
0.1%
top 65.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateMay 13

Description

Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: DGS RES Online, FMS Sender, FMS Receiver, OHC WPF Security). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Cruise Shipboard Property Management System executes to compromise Oracle Hospitality Cruise Shipboard Property Management

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.5 | Impact: 2.5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wgx9-ggvp-ch4q: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: DGS RE2022-05-13
CVEList
CVE-2019-2410: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: DGS RE2019-01-16

💬Community

1
Bugzilla
CVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig2019-09-26
CVE-2019-2410 — MEDIUM severity | cvebase