Vulnerability in Oracle Hospitality Simphony Affects Food and Beverage Applications
CVE-2025-30686

7.6HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability exists in Oracle Hospitality Simphony, which affects versions 19.1 to 19.7. This easily exploitable flaw enables low-privilege attackers with network access via HTTP to compromise the system. An attacker can gain unauthorized access to sensitive information or manipulate data within Oracle Hospitality Simphony, leading to potential data breaches or integrity issues. Additionally, the vulnerability may allow for unauthorized updates or deletions, as well as causing a partial denial of service, impacting the overall availability of the application. It is critical for users of Oracle Hospitality Simphony to implement necessary security measures to mitigate potential risks.

Affected Version(s)

Oracle Hospitality Simphony 19.1 <= 19.7

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.