CVE-2018-2636 is a critical vulnerability affecting Oracle Hospitality Simphony versions 2.7, 2.8, and 2.9, specifically within its Security subcomponent. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the system, potentially leading to a complete takeover. Despite being difficult to exploit, successful attacks can result in high impacts to confidentiality, integrity, and availability, as reflected by its CVSS 3.0 Base Score of 8.1 (HIGH). While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-43960) details a directory traversal vulnerability, and it has garnered significant community discussion and media coverage, indicating notable attention from researchers and the public.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.7CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_simphony:2.7:*:*:*:*:*:*:* | ||
2.8CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_simphony:2.8:*:*:*:*:*:*:* | ||
2.9CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_simphony:2.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.