Impact
Easily exploitable flaw allows an unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony, potentially leading to unauthorized access to critical data or complete exposure of all accessible data. The weakness enables an attacker to bypass authentication controls and read sensitive information, resulting in a high confidentiality impact. This can be categorized as improper access control (CWE-284) and information exposure (CWE-200).
Affected Systems
Affected are Oracle Corporation’s Oracle Hospitality Simphony versions 19.8 through 19.8.5, 19.9 through 19.9.3 and 19.10. The product is part of Oracle Food and Beverage Applications, specifically the POS component.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 reflects a high confidentiality impact with no privilege or user interaction required. The EPSS score is below 1%, indicating low current exploitation probability, yet the vulnerability remains in the public domain and is not listed in CISA’s KEV catalog. The attack vector is inferred to be over the network via standard HTTP traffic, making the exposure feasible in most public or shared environments.
OpenCVE Enrichment