Unauthorized Access Vulnerability in Oracle Hospitality Reporting and Analytics
CVE-2021-1997

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 January 2021

Summary

A vulnerability exists in Oracle Hospitality Reporting and Analytics that permits low privileged attackers with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, granting attackers access to sensitive information within the application. The affected version is 9.1.0, and it is crucial for users of Oracle's food and beverage solutions to assess their environments and implement necessary security measures to mitigate potential risks.

Affected Version(s)

Hospitality Reporting and Analytics 9.1.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.