Exploitable Vulnerability in Oracle Food and Beverage Applications Reporting and Analytics
CVE-2019-2937
8.1HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 16 October 2019
Summary
An exploitable vulnerability exists within the Reporting and Analytics component of Oracle's Food and Beverage Applications. This security flaw allows a low-privileged attacker with Admin - Configuration privileges and network access via HTTP to manipulate the affected system. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, granting the attacker extensive access to sensitive information. Entities using version 9.1.0 must take immediate actions to secure their environments to mitigate potential risks.
Affected Version(s)
Hospitality Reporting and Analytics 9.1.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved