Oracle Hospitality Suite8 vulnerabilities

24 known vulnerabilities affecting oracle/hospitality_suite8.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM21

Vulnerabilities

Page 1 of 2
CVE-2021-45105MEDIUMCVSS 5.9v8.13.0v8.14.02021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2021-41182MEDIUMCVSS 6.1≥ 8.11.0, ≤ 8.14.0v8.10.22021-10-26
CVE-2021-41182 [MEDIUM] CWE-79 CVE-2021-41182: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not acc
nvd
CVE-2021-41183MEDIUMCVSS 6.1≥ 8.11.0, ≤ 11.14.0v8.10.22021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
nvd
CVE-2021-41184MEDIUMCVSS 6.1≥ 8.11.0, ≤ 8.14.0v8.10.22021-10-26
CVE-2021-41184 [MEDIUM] CWE-79 CVE-2021-41184: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the val
nvd
CVE-2021-2351HIGHCVSS 7.5v8.10.2v8.11.0+3 more2021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2020-14810MEDIUMCVSS 5.4≥ 8.11, ≤ 8.14v8.10.22020-10-21
CVE-2020-14810 [MEDIUM] CVE-2020-14810: Vulnerability in the Oracle Hospitality Suite8 product of Oracle Hospitality Applications (component Vulnerability in the Oracle Hospitality Suite8 product of Oracle Hospitality Applications (component: WebConnect). Supported versions that are affected are 8.10.2 and 8.11-8.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction f
nvd
CVE-2019-10219MEDIUMCVSS 6.1v8.10.2v8.11.0+3 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-2781MEDIUMCVSS 6.5≥ 8.11, ≤ 8.14v8.9.6+1 more2019-07-23
CVE-2019-2781 [MEDIUM] CVE-2019-2781: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: XML Interface). Supported versions that are affected are 8.9.6, 8.10.2 and 8.11-8.14. Easily exploitable vulnerability allows low privileged attacker with network access via TCP/IP to compromise Oracle Hospitality Suite8. Successful attacks of this vulne
nvd
CVE-2018-2827HIGHCVSS 7.6≥ 8.9.0, ≤ 8.9.6.30v8.10.0+4 more2018-04-19
CVE-2018-2827 [HIGH] CVE-2018-2827: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Profile). The supported version that is affected is 8.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction from a person other
nvd
CVE-2017-10050HIGHCVSS 8.2v8.10.1v8.10.22017-10-19
CVE-2017-10050 [HIGH] CVE-2017-10050: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction f
nvd
CVE-2017-10337MEDIUMCVSS 5.4v8.10.1v8.10.22017-10-19
CVE-2017-10337 [MEDIUM] CWE-200 CVE-2017-10337: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability
nvd
CVE-2017-10319MEDIUMCVSS 5.3v8.10.1v8.10.22017-10-19
CVE-2017-10319 [MEDIUM] CWE-200 CVE-2017-10319: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerabilit
nvd
CVE-2017-10316MEDIUMCVSS 6.5v8.10.1v8.10.22017-10-19
CVE-2017-10316 [MEDIUM] CWE-200 CVE-2017-10316: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerabil
nvd
CVE-2017-10317MEDIUMCVSS 4.0v8.10.1v8.10.22017-10-19
CVE-2017-10317 [MEDIUM] CWE-200 CVE-2017-10317: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Suite8 executes to compromise Oracle Hospitality
nvd
CVE-2017-10389MEDIUMCVSS 5.7v8.10.1v8.10.22017-10-19
CVE-2017-10389 [MEDIUM] CVE-2017-10389: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: PMS). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Suite8 executes to compromise Oracle Hospitality Suite8. Success
nvd
CVE-2017-10339MEDIUMCVSS 5.9v8.10.1v8.10.22017-10-19
CVE-2017-10339 [MEDIUM] CWE-200 CVE-2017-10339: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnera
nvd
CVE-2017-10419MEDIUMCVSS 5.1v8.10.1v8.10.22017-10-19
CVE-2017-10419 [MEDIUM] CVE-2017-10419: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: PMS). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality Suite8 executes to compromise Oracle Hospitality Suite8. Succes
nvd
CVE-2017-10421MEDIUMCVSS 6.5v8.10.1v8.10.22017-10-19
CVE-2017-10421 [MEDIUM] CWE-200 CVE-2017-10421: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks of this vulnerability
nvd
CVE-2017-10318MEDIUMCVSS 4.7v8.10.1v8.10.22017-10-19
CVE-2017-10318 [MEDIUM] CWE-200 CVE-2017-10318: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human int
nvd
CVE-2017-10420MEDIUMCVSS 6.4v8.10.1v8.10.22017-10-19
CVE-2017-10420 [MEDIUM] CVE-2017-10420: Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomp Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Suite8. While the vulnerability is in Oracle Hospitality
nvd