Unauthenticated Access Vulnerability in Oracle Hospitality OPERA 5 by Oracle
CVE-2025-21547
9.1CRITICAL
Summary
An unauthenticated remote access vulnerability exists in Oracle Hospitality OPERA 5, allowing attackers with network access via HTTP to exploit the system. Affected versions include 5.6.19.20, 5.6.25.8, 5.6.26.6, and 5.6.27.1. Successful exploitation can lead to unauthorized access to critical data and the potential for Denial of Service, where the application may hang or experience frequent crashes. This poses significant risks to data confidentiality and system availability.
Affected Version(s)
Oracle Hospitality OPERA 5 5.6.19.20
Oracle Hospitality OPERA 5 5.6.25.8
Oracle Hospitality OPERA 5 5.6.26.6
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved