Vulnerability in Oracle Hospitality OPERA 5 Property Services
CVE-2017-3574
7.1HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 24 April 2017
Summary
The Oracle Hospitality OPERA 5 Property Services includes a network access vulnerability that can be exploited by low-privileged attackers with HTTP access. This security flaw can lead to unauthorized access to sensitive information, allowing attackers to read, modify, or manipulate data within the OPERA system. It affects several versions of the OPERA 5 solution and can result in critical breaches affecting data integrity and confidentiality.
Affected Version(s)
Hospitality OPERA 5 Property Services 5.4.0.x
Hospitality OPERA 5 Property Services 5.4.1.x
Hospitality OPERA 5 Property Services 5.4.2.x
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved