Oracle Hospitality Opera 5 vulnerabilities
10 known vulnerabilities affecting oracle/hospitality_opera_5.
Total CVEs
10
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH4MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-21967HIGHCVSS 8.6v5.6.19.23v5.6.25.17+2 more2026-01-20
CVE-2026-21967 [HIGH] CVE-2026-21967: Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (componen
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5.6.27.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successful attacks
nvd
CVE-2026-21966MEDIUMCVSS 6.1v5.6.19.23v5.6.25.17+2 more2026-01-20
CVE-2026-21966 [MEDIUM] CVE-2026-21966: Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Appl
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5.6.27.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property
nvd
CVE-2025-21547CRITICALCVSS 9.1v5.6.19.20v5.6.25.8+2 more2025-01-21
CVE-2025-21547 [CRITICAL] CWE-400 CVE-2025-21547: Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (componen
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.20, 5.6.25.8, 5.6.26.6 and 5.6.27.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. Successfu
nvd
CVE-2024-21172CRITICALCVSS 9.0v5.6.19.19v5.6.25.8+1 more2024-10-15
CVE-2024-21172 [CRITICAL] CVE-2024-21172: Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (componen
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.19, 5.6.25.8 and 5.6.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. While the vulnerability i
nvd
CVE-2021-2351HIGHCVSS 7.5v5.62021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2020-17530CRITICALCVSS 9.8KEVPoCv5.62020-12-11
CVE-2020-17530 [CRITICAL] CWE-917 CVE-2020-17530: Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
nvd
CVE-2020-17521MEDIUMCVSS 5.5v5.62020-12-07
CVE-2020-17521 [MEDIUM] CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this f
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected,
nvd
CVE-2019-17566HIGHCVSS 7.5v5.5v5.62020-11-12
CVE-2019-17566 [HIGH] CWE-918 CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by th
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2018-1285CRITICALCVSS 9.8v5.5v5.62020-05-11
CVE-2018-1285 [CRITICAL] CWE-611 CVE-2018-1285: Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net conf
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
nvd
CVE-2019-10086HIGHCVSS 7.3v5.5v5.62019-08-20
CVE-2019-10086 [HIGH] CWE-502 CVE-2019-10086: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressi
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
nvd