First published: Tue Oct 15 2024(Updated: )
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.19, 5.6.25.8 and 5.6.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. While the vulnerability is in Oracle Hospitality OPERA 5, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Hospitality OPERA | =5.6.19.19 | |
Oracle Hospitality OPERA | =5.6.25.8 | |
Oracle Hospitality OPERA | =5.6.26.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21172 has been classified with a severity that indicates it poses a significant risk to affected Oracle Hospitality OPERA 5 versions.
To fix CVE-2024-21172, users should update their Oracle Hospitality OPERA 5 software to a supported version that has patched this vulnerability.
CVE-2024-21172 affects users of Oracle Hospitality OPERA 5 versions 5.6.19.19, 5.6.25.8, and 5.6.26.4.
Yes, CVE-2024-21172 can be exploited by an unauthenticated attacker with network access via HTTP.
CVE-2024-21172 involves a vulnerability in the Opera Servlet component of the Oracle Hospitality OPERA 5 product.