Known Vulnerabilities for Internet Reservation Module Next Generation by Resortdata
Listed below are 5 of the newest known vulnerabilities associated with "Internet Reservation Module Next Generation" by "Resortdata".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-39424 json | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to uplo... | 8.8 - HIGH | 2023-09-07 | 2023-09-12 |
| CVE-2023-39423 json | The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a U... | 9.1 - CRITICAL | 2023-09-07 | 2023-09-12 |
| CVE-2023-39422 json | The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. The... | 9.8 - CRITICAL | 2023-09-07 | 2023-09-12 |
| CVE-2023-39421 json | The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-par... | 7.7 - HIGH | 2023-09-07 | 2023-09-12 |
| CVE-2023-39420 json | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers wit... | 8.8 - HIGH | 2023-09-07 | 2023-09-12 |