Vulnerability in Oracle Hospitality OPERA 5 Property Services
CVE-2017-3574

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

The Oracle Hospitality OPERA 5 Property Services includes a network access vulnerability that can be exploited by low-privileged attackers with HTTP access. This security flaw can lead to unauthorized access to sensitive information, allowing attackers to read, modify, or manipulate data within the OPERA system. It affects several versions of the OPERA 5 solution and can result in critical breaches affecting data integrity and confidentiality.

Affected Version(s)

Hospitality OPERA 5 Property Services 5.4.0.x

Hospitality OPERA 5 Property Services 5.4.1.x

Hospitality OPERA 5 Property Services 5.4.2.x

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.