Improper input validation in Oracle Hospitality Cruise Shipboard Property Management System - CVE-2019-2410

 

Improper input validation in Oracle Hospitality Cruise Shipboard Property Management System - CVE-2019-2410

Published: December 24, 2024


Vulnerability identifier: #VU121847
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2410
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to read and manipulate data.

The vulnerability exists due to improper input validation within the DGS RES Online, FMS Sender, FMS Receiver, OHC WPF Security component in Oracle Hospitality Cruise Shipboard Property Management System. A local non-authenticated attacker can exploit this vulnerability to read and manipulate data.


Affected software

Oracle Hospitality Cruise Shipboard Property Management System

How to mitigate CVE-2019-2410

Install updates from vendor's website.


External References

Related Security Bulletins