Vulnerability in Oracle Hospitality Simphony First Edition Component
CVE-2018-2853
5.4MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 19 April 2018
What is CVE-2018-2853?
An improper access control vulnerability exists in the Oracle Hospitality Simphony First Edition, specifically within the operations of the Client Application Loader. This vulnerability could potentially allow a low-privileged attacker with network access via HTTP to gain unauthorized access. Successful exploitation may result in unauthorized modifications and reading of sensitive data, as the vulnerability provides a pathway for unauthorized updates, inserts, or deletions of accessible data within the Oracle Hospitality Simphony environment.
Affected Version(s)
Hospitality Simphony First Edition 1.6
Hospitality Simphony First Edition 1.7