Vulnerability in Oracle Hospitality Simphony First Edition Component
CVE-2018-2853

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
19 April 2018

What is CVE-2018-2853?

An improper access control vulnerability exists in the Oracle Hospitality Simphony First Edition, specifically within the operations of the Client Application Loader. This vulnerability could potentially allow a low-privileged attacker with network access via HTTP to gain unauthorized access. Successful exploitation may result in unauthorized modifications and reading of sensitive data, as the vulnerability provides a pathway for unauthorized updates, inserts, or deletions of accessible data within the Oracle Hospitality Simphony environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Hospitality Simphony First Edition 1.6

Hospitality Simphony First Edition 1.7

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.