Impact
Oracle Hospitality Simphony, part of Oracle Food and Beverage Applications, contains a point‑of‑sale component that has an unauthenticated remote code execution vulnerability. The flaw, identified as CWE‑306 (Missing Authentication for Critical Function), permits an attacker with network access over HTTP to perform unauthorized operations. If successfully exploited, the attacker can take full control of the Simphony instance, compromising confidentiality, integrity, and availability of the point‑of‑sale system.
Affected Systems
The vulnerability affects Oracle Hospitality Simphony deployments that are part of Oracle Food and Beverage Applications. Supported affected versions are 19.8 through 19.8.5, 19.9 through 19.9.3, and the 19.10 release. These systems are typically used as point‑of‑sale solutions in restaurants, hotels, resorts, and other hospitality venues.
Risk and Exploitability
The CVSS base score of 8.1 denotes a high severity flaw. The attack vector is network‑based, with no authentication or user interaction required. The EPSS score is less than 1%, indicating a low probability of active exploitation at present, but no confirmation of exploitation is reported in the CISA KEV catalog. The asymmetry of impact—full takeover of Simphony—makes mitigating the flaw a priority even if active exploitation is currently rare.
OpenCVE Enrichment