Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-21547

Опубликовано: 21 янв. 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.20, 5.6.25.8, 5.6.26.6 and 5.6.27.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oracle:hospitality_opera_5:5.6.19.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5:5.6.25.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5:5.6.26.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hospitality_opera_5:5.6.27.1:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00319
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 9.1
github
около 1 года назад

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.20, 5.6.25.8, 5.6.26.6 and 5.6.27.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

EPSS

Процентиль: 54%
0.00319
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-400