Impact
The flaw resides in the Oracle Hospitality Simphony POS component and is a result of improper authentication and access control weaknesses (CWE-284). An attacker who can reach the Simphony HTTP endpoint does not need credentials and can use the vulnerability to read any data the application handles, effectively bypassing authentication controls and gaining direct, unauthorized access to critical business information.
Affected Systems
Oracle Hospitality Simphony, part of Oracle Food and Beverage Applications, is affected. Versions 19.8 through 19.8.5, 19.9 through 19.9.3, and 19.10 contain the vulnerability. The issue lies in the POS module and applies to any instance exposed to the network.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates moderate‑high severity, primarily impacting confidentiality. The EPSS score of less than 1% shows a very low but non‑zero probability of exploitation under current data. Because the vulnerability is not listed in the CISA KEV catalog, there is no confirmed exploitation evidence. Attackers would need network access to the Simphony HTTP endpoint; no authentication is required, so unauthorized data exposure can occur quickly. Reducing risk requires prompt patching, restricting inbound HTTP traffic, and vigilant monitoring of anomalous requests.
OpenCVE Enrichment