CVE-2018-2700 is a high-severity vulnerability affecting the Emergency Response System subcomponent within Oracle Hospitality Cruise Fleet Management version 9.0.4.0. This easily exploitable flaw allows an unauthenticated attacker to compromise the system via HTTP network access. Successful exploitation grants unauthorized access to critical data, potentially leading to complete data compromise within the affected system. The vulnerability has a CVSS 3.0 Base Score of 7.5 (High), indicating a network-based attack vector with low attack complexity and no user interaction required. Its primary impact is on confidentiality, allowing full data disclosure. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_cruise_fleet_management:9.0.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.