CVE-2025-21547: Critical severity oracle hospitality opera vulnerability
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.20, 5.6.25.8, 5.6.26.6 and 5.6.27.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21547?
CVE-2025-21547 has been classified as an easily exploitable vulnerability that poses significant risk to affected versions.
How do I fix CVE-2025-21547?
To fix CVE-2025-21547, apply the latest security patches provided by Oracle for the affected versions 5.6.19.20, 5.6.25.8, 5.6.26.6, and 5.6.27.1.
What products are affected by CVE-2025-21547?
CVE-2025-21547 affects multiple versions of the Oracle Hospitality OPERA 5 product, specifically versions 5.6.19.20, 5.6.25.8, 5.6.26.6, and 5.6.27.1.
Can CVE-2025-21547 be exploited remotely?
Yes, CVE-2025-21547 is an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise the system.
What should organizations using Oracle Hospitality OPERA 5 do about CVE-2025-21547?
Organizations using Oracle Hospitality OPERA 5 should immediately assess their systems for the affected versions and implement recommended security patches.