Vulnerability in Oracle Hospitality Reporting and Analytics Affects Oracle Food and Beverage Applications
CVE-2019-2934

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 October 2019

Summary

A vulnerability exists in the Oracle Hospitality Reporting and Analytics component, which allows low privileged attackers with Admin - Configuration privileges to exploit the system via HTTP. This could potentially lead to unauthorized creation, modification, or deletion of critical data, compromising the integrity and confidentiality of all accessible data within Oracle Hospitality Reporting and Analytics.

Affected Version(s)

Hospitality Reporting and Analytics 9.1.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.