CVE-2024-21172
CVSS 3.1 Score 9 of 10 (high)
Details
Summary
CVE-2024-21172 is a newly disclosed vulnerability affecting the Oracle Hospitality OPERA 5 product, specifically the Opera Servlet component. Impacted versions include 5.6.19.19, 5.6.25.8, and 5.6.26.4. This issue enables unauthenticated attackers, with only network access via HTTP, to compromise Oracle Hospitality OPERA 5. Although the vulnerability resides within Oracle Hospitality OPERA 5, its exploitation may extend to other affected products, leading to significant scope changes. Successfully exploiting this difficulty-to-exploit flaw can result in complete takeover of Oracle Hospitality OPERA 5, posing risks to confidentiality, integrity, and availability. According to the CVSS 3.1 Base Score, the vulnerability holds a severity level of 9.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.