CVE-2017-10189 is a vulnerability in the Leisure subcomponent of Oracle Hospitality Suite8, affecting version 8.10.x. This easily exploitable flaw allows a low-privileged attacker with infrastructure logon to gain unauthorized access to critical or all data within Hospitality Suite8. With a CVSS 3.0 Base Score of 5.5 (Medium), it primarily impacts confidentiality, requiring local access and low privileges without user interaction. There is no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog, indicating no active exploitation. While there are a few community mentions, media coverage is absent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.10.0CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_suite8:8.10.0:*:*:*:*:*:*:* | ||
8.10.1CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_suite8:8.10.1:*:*:*:*:*:*:* | ||
8.10.2CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_suite8:8.10.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.