Exploitable Vulnerability in Oracle Food and Beverage Applications Reporting and Analytics
CVE-2019-2937

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 October 2019

Summary

An exploitable vulnerability exists within the Reporting and Analytics component of Oracle's Food and Beverage Applications. This security flaw allows a low-privileged attacker with Admin - Configuration privileges and network access via HTTP to manipulate the affected system. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, granting the attacker extensive access to sensitive information. Entities using version 9.1.0 must take immediate actions to secure their environments to mitigate potential risks.

Affected Version(s)

Hospitality Reporting and Analytics 9.1.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.