CVE-2025-30686

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 21, 2025
CWE ID 497

Summary

CVE-2025-30686 is a vulnerability affecting Oracle Food and Beverage Applications' Oracle Hospitality Simphony product (EMC component). Versions 19.1 to 19.7 are impacted. A low-privileged attacker with network access via HTTP can exploit this easily exploitable issue, potentially gaining unauthorized access to critical data or complete access to all Oracle Hospitality Simphony data. Additionally, attackers can manipulate some data and cause a partial denial of service. The Base Score is 7.6, with Confidentiality, Integrity, and Availability impacts. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle Hospitality Simphony

Affected Vendors

  • Oracle