cbcvebase.

Oracle Hospitality Guest Access vulnerabilities

34 known vulnerabilities affecting oracle/hospitality_guest_access.

Total CVEs
34
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
7
Severity breakdown
CRITICAL2HIGH10MEDIUM22

Vulnerabilities

Page 2 of 2
CVE-2018-2852P4MEDIUMCVSS 6.4v4.2.0v4.2.12018-04-19
CVE-2018-2852 [MEDIUM] CVE-2018-2852: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. While the vulnerability is in Oracle Hospit
nvd
CVE-2019-10247P4MEDIUMCVSS 5.3v4.2.0v4.2.12019-04-22
CVE-2019-10247 [MEDIUM] CWE-213 CVE-2019-10247: In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the ser In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on je
nvd
CVE-2018-11039P4MEDIUMCVSS 5.9v4.2.0v4.2.12018-06-25
CVE-2018-11039 [MEDIUM] CVE-2018-11039: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupport Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filt
nvd
CVE-2019-10246P4MEDIUMCVSS 5.3v4.2.0v4.2.12019-04-22
CVE-2019-10246 [MEDIUM] CWE-213 CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource dire
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8v4.2.0v4.2.12020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2019-17569P4MEDIUMCVSS 4.8v4.2.0v4.2.12020-02-24
CVE-2019-17569 [MEDIUM] CWE-444 CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 int The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the inval
nvd
CVE-2017-10370P4MEDIUMCVSS 6.9v4.2.0v4.2.12017-10-19
CVE-2017-10370 [MEDIUM] CVE-2017-10370: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks require human interac
nvd
CVE-2017-10383P4MEDIUMCVSS 5.3v4.2.0v4.2.12017-10-19
CVE-2017-10383 [MEDIUM] CWE-200 CVE-2017-10383: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Interface). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this
nvd
CVE-2018-2606P4MEDIUMCVSS 6.2v4.2.0v4.2.12018-01-18
CVE-2018-2606 [MEDIUM] CVE-2018-2606: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Guest Access executes to compromise Oracle Hospitality Guest
nvd
CVE-2017-10219P4MEDIUMCVSS 5.5v4.2.0.0v4.2.1.02017-08-08
CVE-2017-10219 [MEDIUM] CVE-2017-10219: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Guest Access executes to compromise Oracle Hospitality
nvd
CVE-2017-10218P4MEDIUMCVSS 4.3v4.2.0.0v4.2.1.02017-08-08
CVE-2017-10218 [MEDIUM] CVE-2017-10218: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerabil
nvd
CVE-2017-10217P4MEDIUMCVSS 4.3v4.2.0.0v4.2.1.02017-08-08
CVE-2017-10217 [MEDIUM] CVE-2017-10217: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerabil
nvd
CVE-2017-10375P4MEDIUMCVSS 4.6v4.2.0v4.2.12017-10-19
CVE-2017-10375 [MEDIUM] CVE-2017-10375: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks require human interact
nvd
CVE-2018-2607P4MEDIUMCVSS 4.9v4.2.12018-01-18
CVE-2018-2607 [MEDIUM] CVE-2018-2607: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). The supported version that is affected is 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result
nvd