CVE-2018-2957: High severity oracle hospitality opera vulnerability
Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: Logging). The supported version that is affected is 5.5.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2957?
CVE-2018-2957 is rated as high severity due to its potential to allow unauthenticated attackers to compromise Oracle Hospitality OPERA 5 Property Services.
How do I fix CVE-2018-2957?
To resolve CVE-2018-2957, upgrade your Oracle Hospitality OPERA Property Management software to the latest version available beyond 5.5.x.
What versions of Oracle Hospitality are affected by CVE-2018-2957?
CVE-2018-2957 affects the Oracle Hospitality OPERA Property Management software versions 5.5 and 5.5.1.
Can CVE-2018-2957 be exploited remotely?
Yes, CVE-2018-2957 can be exploited remotely by attackers with network access via HTTP.
What component of Oracle Hospitality is impacted by CVE-2018-2957?
CVE-2018-2957 impacts the Logging component of the Oracle Hospitality OPERA 5 Property Services.