Impact
A flaw in Oracle Hospitality Simphony permits any unauthenticated user to reach the system through HTTP and create, delete, or modify critical data, while also triggering crashes that can cause a hang or repeated service interruptions. The vulnerability results in high impact to both data integrity and service availability, reflecting a classic improper access control weakness.
Affected Systems
Oracle Corporation’s Oracle Hospitality Simphony – affected versions include 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 denotes high severity, yet the EPSS score of less than 1 % indicates a low current exploitation likelihood; the vulnerability is not listed in the CISA KEV catalog. Attackers require only network access to exposed HTTP endpoints and no authentication, making the flaw theoretically easily exploitable, though it is not widely abused in practice.
OpenCVE Enrichment