Impact
The flaw lies in the Opera Servlet component of Oracle Hospitality OPERA 5 Property Services, allowing an unauthenticated attacker to send HTTP requests that are processed as legitimate interactions. When a second party assists by providing human interaction, the attacker can then compromise the application, leading to full system takeover and affecting confidentiality, integrity, and availability. This weakness aligns with CWE-284, Authorization.
Affected Systems
Oracle Hospitality OPERA 5 Property Services, versions 5.6.28.0 through 5.6.28.1, from Oracle Hospitality Applications.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity. Exploit requires only network connectivity to the exposed HTTP interface and no authentication, though a user interaction step remains necessary. The EPSS score is less than 1%, suggesting low exploitation probability, and the vulnerability is not yet listed in CISA’s KEV catalog. Nonetheless, the high CVSS and potential for full takeover make this a serious risk for environments that expose the service to untrusted networks.
OpenCVE Enrichment