Oracle Hospitality Cruise Shipboard Property Management System vulnerabilities

16 known vulnerabilities affecting oracle/hospitality_cruise_shipboard_property_management_system.

Total CVEs
16
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM9

Vulnerabilities

Page 1 of 1
CVE-2022-29885HIGHCVSS 7.5PoCv20.2.12022-05-12
CVE-2022-29885 [HIGH] CWE-400 CVE-2022-29885: The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 a The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protec
nvd
CVE-2021-42340HIGHCVSS 7.5v20.1.02021-10-14
CVE-2021-42340 [HIGH] CWE-772 CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could le
nvd
CVE-2021-33037MEDIUMCVSS 5.3v20.1.02021-07-12
CVE-2021-33037 [MEDIUM] CWE-444 CVE-2021-33037: Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse th Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only
nvd
CVE-2021-30640MEDIUMCVSS 6.5v20.1.02021-07-12
CVE-2021-30640 [MEDIUM] CWE-116 CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variatio A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
nvd
CVE-2021-22112HIGHCVSS 8.8v20.1.02021-02-23
CVE-2021-22112 [HIGH] CVE-2021-22112: Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, an Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to r
nvd
CVE-2019-10219MEDIUMCVSS 6.1v20.1.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-2411HIGHCVSS 7.6v8.0.82019-01-16
CVE-2019-2411 [HIGH] CVE-2019-2411: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Hospitality Cruise Shipboard Property Manage
nvd
CVE-2019-2410MEDIUMCVSS 5.1v8.0.82019-01-16
CVE-2019-2410 [MEDIUM] CVE-2019-2410: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: DGS RES Online, FMS Sender, FMS Receiver, OHC WPF Security). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Ora
nvd
CVE-2019-2409MEDIUMCVSS 6.7v8.0.82019-01-16
CVE-2019-2409 [MEDIUM] CVE-2019-2409: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Cruise Shipboard Property Managem
nvd
CVE-2018-3160HIGHCVSS 7.7v8.02018-10-17
CVE-2018-3160 [HIGH] CVE-2018-3160: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: OHC Admin, OHC Management). The supported version that is affected is 8.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hospitality Cruise Shipboard Prop
nvd
CVE-2018-3181MEDIUMCVSS 5.5v8.02018-10-17
CVE-2018-3181 [MEDIUM] CVE-2018-3181: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: OHC ENOAD). The supported version that is affected is 8.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Cruise Shipboard Property Management
nvd
CVE-2018-3000HIGHCVSS 7.1v8.02018-07-18
CVE-2018-3000 [HIGH] CVE-2018-3000: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Cruise Shipboard Property Management
nvd
CVE-2018-3001MEDIUMCVSS 6.2v8.02018-07-18
CVE-2018-3001 [MEDIUM] CVE-2018-3001: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: SPMS Suite). The supported version that is affected is 8.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Cruise Shipboard Property Manageme
nvd
CVE-2018-2621HIGHCVSS 8.2v7.3.8742018-01-18
CVE-2018-2621 [HIGH] CVE-2018-2621: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: Mobile Gangway and Mustering). The supported version that is affected is 7.3.874. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shi
nvd
CVE-2017-10361MEDIUMCVSS 6.4v8.0.2.02017-10-19
CVE-2017-10361 [MEDIUM] CVE-2017-10361: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: OHC DRS). The supported version that is affected is 8.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Ma
nvd
CVE-2017-10228MEDIUMCVSS 5.4v8.0.0.02017-08-08
CVE-2017-10228 [MEDIUM] CVE-2017-10228: Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Ora Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System component of Oracle Hospitality Applications (subcomponent: Module). The supported version that is affected is 8.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Man
nvd