Oracle Hospitality Reporting and Analytics Vulnerability in Food and Beverage Applications
CVE-2018-3128
8.1HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 17 October 2018
Summary
A significant vulnerability exists in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications, particularly impacting version 9.0. This flaw allows an attacker with limited privileges to exploit the system via HTTP, leading to unauthorized actions such as creation, deletion, or alteration of critical data. Additionally, the vulnerability may enable the attacker to gain complete access to sensitive information within the Oracle Hospitality Reporting and Analytics framework, thereby compromising the confidentiality and integrity of the data.
Affected Version(s)
Hospitality Reporting and Analytics 9.0
Hospitality Reporting and Analytics 9.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved