Unauthorized Access Vulnerability in Oracle Hospitality Reporting and Analytics
CVE-2021-1997
8.1HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 January 2021
Summary
A vulnerability exists in Oracle Hospitality Reporting and Analytics that permits low privileged attackers with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, granting attackers access to sensitive information within the application. The affected version is 9.1.0, and it is crucial for users of Oracle's food and beverage solutions to assess their environments and implement necessary security measures to mitigate potential risks.
Affected Version(s)
Hospitality Reporting and Analytics 9.1.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved