Oracle Hospitality OPERA 5 Property Services Vulnerability Exposes Critical Data
CVE-2023-21932

7.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability in Oracle Hospitality OPERA 5 Property Services could allow a high-privileged attacker with network access to HTTP interfaces to gain unauthorized access to sensitive data. Although primarily affecting OPERA 5, the implications of this vulnerability may extend to other related Oracle applications, emphasizing the risk of unauthorized data manipulation, including insert, delete, and update operations. Furthermore, the potential for a partial denial of service could disrupt operations, affecting both confidentiality and availability of data within the system.

Affected Version(s)

Hospitality OPERA 5 Property Services 5.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.