cbcvebase.
CVE-2024-21172
published 2024-10-15

CVE-2024-21172: Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are…

PriorityP357critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
EPSS
0.48%
38.4th percentile
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.19, 5.6.25.8 and 5.6.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. While the vulnerability is in Oracle Hospitality OPERA 5, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

Affected

6 ranges
VendorProductVersion rangeFixed in
oraclehospitality_opera_5
oraclehospitality_opera_5
oraclehospitality_opera_5
oracle_corporationoracle_hospitality_opera_5
oracle_corporationoracle_hospitality_opera_5
oracle_corporationoracle_hospitality_opera_5

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerable component is the Opera Servlet, accessible via HTTP. Monitor for unauthenticated HTTP requests targeting Oracle Hospitality OPERA 5 servlet endpoints on affected versions (5.6.19.19, 5.6.25.8, 5.6.26.4).
  • Scope change is indicated — successful exploitation may pivot to compromise additional products beyond OPERA 5 itself. Investigate lateral movement or secondary system compromise following any OPERA 5 servlet anomaly.
  • ·Exploitation is rated 'Difficult' (AC:H), meaning special conditions must be met. Not all unauthenticated HTTP traffic to the servlet is malicious; focus on anomalous or repeated access patterns.
  • ·Only three specific versions are confirmed affected: 5.6.19.19, 5.6.25.8, and 5.6.26.4. Detection efforts should be scoped to environments running these exact versions.
  • ·No Red Hat products are affected; detection and patching efforts should focus solely on Oracle Hospitality OPERA 5 deployments.

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_oracle9.0CRITICAL
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.