Improper input validation in Oracle Hospitality Cruise Shipboard Property Management System - CVE-2019-2410

 

Improper input validation in Oracle Hospitality Cruise Shipboard Property Management System - CVE-2019-2410

Published: December 24, 2024


Vulnerability identifier: #VU121847
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-2410
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Oracle
Affected software:
Oracle Hospitality Cruise Shipboard Property Management System

Detailed vulnerability description

The vulnerability allows a local non-authenticated attacker to read and manipulate data.

The vulnerability exists due to improper input validation within the DGS RES Online, FMS Sender, FMS Receiver, OHC WPF Security component in Oracle Hospitality Cruise Shipboard Property Management System. A local non-authenticated attacker can exploit this vulnerability to read and manipulate data.


How to mitigate CVE-2019-2410

Install updates from vendor's website.

Sources