First published: Wed Oct 21 2020(Updated: )
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Logging). Supported versions that are affected are 5.5 and 5.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Hospitality OPERA | =5.5 | |
Oracle Hospitality OPERA | =5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14858.
The affected software is Oracle Hospitality OPERA 5 Property Services versions 5.5 and 5.6.
The severity of CVE-2020-14858 is high with a CVSS score of 6.8.
The vulnerability can be exploited by a high privileged attacker with network access via HTTP.
Please refer to the official Oracle security advisory for information on fixes or patches for CVE-2020-14858.