Unauthorized Access Vulnerability in Oracle Hospitality Simphony by Oracle
CVE-2019-2833

7.7HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

A vulnerability exists in Oracle Hospitality Simphony that allows an attacker with low privileges, specifically Import/Export access and network connectivity through HTTP, to exploit the system. This can lead to unauthorized access to sensitive data and potentially control over all data accessible through the Oracle Hospitality Simphony platform. The severity of this vulnerability should not be underestimated, as successful exploitation may significantly affect other interconnected products within the Oracle Food and Beverage Applications framework.

Affected Version(s)

Hospitality Simphony 18.2.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.