Unauthenticated Network Vulnerability in Oracle Hospitality OPERA 5 Property Services
CVE-2018-2955
5.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 July 2018
Summary
A vulnerability exists in the Oracle Hospitality OPERA 5 Property Services component, specifically within the Integration subcomponent. This vulnerability allows an unauthenticated attacker to exploit network access via HTTP, potentially compromising the data integrity of Oracle Hospitality applications. Successful exploitation can lead to unauthorized read access to sensitive data, which poses significant privacy risks to affected systems. Organizations using version 5.5.x of Oracle Hospitality OPERA should assess their security measures and apply necessary patches to mitigate this vulnerability.
Affected Version(s)
Hospitality OPERA 5 Property Services 5.5.x
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved