Oracle Hospitality Guest Access vulnerabilities

34 known vulnerabilities affecting oracle/hospitality_guest_access.

Total CVEs
34
CISA KEV
3
actively exploited
Public exploits
7
Exploited in wild
4
Severity breakdown
CRITICAL2HIGH10MEDIUM22

Vulnerabilities

Page 2 of 2
CVE-2018-2604HIGHCVSS 7.5v4.2.12018-01-18
CVE-2018-2604 [HIGH] CVE-2018-2604: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). The supported version that is affected is 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result i
nvd
CVE-2018-2606MEDIUMCVSS 6.2v4.2.0v4.2.12018-01-18
CVE-2018-2606 [MEDIUM] CVE-2018-2606: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Guest Access executes to compromise Oracle Hospitality Guest
nvd
CVE-2015-9251MEDIUMCVSS 6.1v4.2.0v4.2.12018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
CVE-2018-2607MEDIUMCVSS 4.9v4.2.12018-01-18
CVE-2018-2607 [MEDIUM] CVE-2018-2607: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). The supported version that is affected is 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerability can result
nvd
CVE-2017-10372HIGHCVSS 8.7v4.2.0v4.2.12017-10-19
CVE-2017-10372 [HIGH] CVE-2017-10372: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. While the vulnerability is in Oracle Hospi
nvd
CVE-2017-10375MEDIUMCVSS 4.6v4.2.0v4.2.12017-10-19
CVE-2017-10375 [MEDIUM] CVE-2017-10375: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks require human interact
nvd
CVE-2017-10370MEDIUMCVSS 6.9v4.2.0v4.2.12017-10-19
CVE-2017-10370 [MEDIUM] CVE-2017-10370: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks require human interac
nvd
CVE-2017-10383MEDIUMCVSS 5.3v4.2.0v4.2.12017-10-19
CVE-2017-10383 [MEDIUM] CWE-200 CVE-2017-10383: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Interface). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this
nvd
CVE-2017-12617HIGHCVSS 8.1KEVPoCv4.2.0v4.2.12017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0. When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2017-10218MEDIUMCVSS 4.3v4.2.0.0v4.2.1.02017-08-08
CVE-2017-10218 [MEDIUM] CVE-2017-10218: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerabil
nvd
CVE-2017-10219MEDIUMCVSS 5.5v4.2.0.0v4.2.1.02017-08-08
CVE-2017-10219 [MEDIUM] CVE-2017-10219: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Guest Access executes to compromise Oracle Hospitality
nvd
CVE-2017-10217MEDIUMCVSS 4.3v4.2.0.0v4.2.1.02017-08-08
CVE-2017-10217 [MEDIUM] CVE-2017-10217: Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (s Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0.0 and 4.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Guest Access. Successful attacks of this vulnerabil
nvd
CVE-2017-9735HIGHCVSS 7.5v4.2.0v4.2.12017-06-16
CVE-2017-9735 [HIGH] CWE-203 CVE-2017-9735: Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easi Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
nvd
CVE-2016-8735CRITICALCVSS 9.8KEVPoCv4.2.0v4.2.12017-04-06
CVE-2016-8735 [CRITICAL] CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8. Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential ty
nvd