vendor:
Hospitality RES 3700
by:
Walid Faour
9.0
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: Hospitality RES 3700
Affected Version From: <= v5.7
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2019-3025
CPE: a:oracle:hospitality_res_3700:5.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2003 / Windows Server 2008
2019
Oracle Hospitality RES 3700 5.7 – Remote Code Execution
This exploit allows an attacker to remotely execute code on a vulnerable Oracle Hospitality RES 3700 Release 4.9 system. The exploit involves sending a specially crafted SOAP request to the vulnerable system, which contains a malicious payload. The payload is then executed on the system, allowing the attacker to gain access to the system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their systems to the latest version of the software.