#VU121847 Improper input validation in Oracle Hospitality Cruise Shipboard Property Management System - CVE-2019-2410

 

#VU121847 Improper input validation in Oracle Hospitality Cruise Shipboard Property Management System - CVE-2019-2410

Published: December 24, 2024


Vulnerability identifier: #VU121847
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-2410
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Oracle Hospitality Cruise Shipboard Property Management System
Software vendor:
Oracle

Description

The vulnerability allows a local non-authenticated attacker to read and manipulate data.

The vulnerability exists due to improper input validation within the DGS RES Online, FMS Sender, FMS Receiver, OHC WPF Security component in Oracle Hospitality Cruise Shipboard Property Management System. A local non-authenticated attacker can exploit this vulnerability to read and manipulate data.


Remediation

Install updates from vendor's website.

External links