CVE-2024-21172

CVSS 3.1 Score 9 of 10 (high)

Confidentiality high
Integrity high
Availability high
Scope changed
Attack Complexity high
Privileges Required none

Details

Published Oct 15, 2024
Updated: Oct 21, 2024

Summary

CVE-2024-21172 is a newly disclosed vulnerability affecting the Oracle Hospitality OPERA 5 product, specifically the Opera Servlet component. Impacted versions include 5.6.19.19, 5.6.25.8, and 5.6.26.4. This issue enables unauthenticated attackers, with only network access via HTTP, to compromise Oracle Hospitality OPERA 5. Although the vulnerability resides within Oracle Hospitality OPERA 5, its exploitation may extend to other affected products, leading to significant scope changes. Successfully exploiting this difficulty-to-exploit flaw can result in complete takeover of Oracle Hospitality OPERA 5, posing risks to confidentiality, integrity, and availability. According to the CVSS 3.1 Base Score, the vulnerability holds a severity level of 9.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share