Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
Fri, 21 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Data Exfiltration in Oracle Hospitality Simphony |
Fri, 21 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Enables Data Disclosure in Oracle Hospitality Simphony | |
| Weaknesses | CWE-200 CWE-287 |
|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Tue, 18 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Enables Data Disclosure in Oracle Hospitality Simphony | |
| Weaknesses | CWE-200 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Supported versions that are affected are 19.8-19.8.5, 19.9-19.9.3 and 19.10-19.10.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle hospitality Simphony |
|
| CPEs | cpe:2.3:a:oracle:hospitality_simphony:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle hospitality Simphony |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-08-20T17:24:18.345Z
Reserved: 2026-07-08T15:51:40.546Z
Link: CVE-2026-60590
Updated: 2026-08-20T17:24:07.092Z
Status : Awaiting Analysis
Published: 2026-08-18T21:16:38.367
Modified: 2026-08-20T18:16:29.330
Link: CVE-2026-60590
No data.
OpenCVE Enrichment
Updated: 2026-08-21T18:00:16Z