Vulnerability in Oracle Hospitality Reporting and Analytics of Oracle Food and Beverage Applications
CVE-2019-2407

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2019

Summary

The vulnerability in the Oracle Hospitality Reporting and Analytics component allows low-privileged attackers with Report privileges to execute unauthorized actions. This exploit enables them to gain access to sensitive data, and potentially manipulate it through updates, inserts, or deletions within the Oracle Hospitality platform. Organizations using version 9.1.0 need to be aware of the risks associated with compromised access, as attackers can exploit this vulnerability to compromise the confidentiality and integrity of vital reporting and analytics data.

Affected Version(s)

Hospitality Reporting and Analytics 9.1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.