cbcvebase.
CVE-2024-21010
published 2024-04-16

CVE-2024-21010: Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions…

PriorityP261critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.73%
50.1th percentile
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Affected

2 ranges
VendorProductVersion rangeFixed in
oraclehospitality_simphony19.1.0 – 19.5.4
oracle_corporationhospitality_simphony19.1.0 – 19.5.4

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability targets Oracle Hospitality Simphony Enterprise Server component via HTTP with low-privilege network access; monitor for anomalous HTTP requests from authenticated low-privileged users against Simphony Enterprise Server endpoints
  • Scope change is indicated — successful exploitation may pivot to additional products beyond Simphony itself; monitor lateral movement from Simphony Enterprise Server hosts
  • Affected versions are 19.1.0 through 19.5.4; prioritize detection and patching on hosts running these specific Simphony Enterprise Server versions
  • ·No authentication bypass — attacker requires a low-privileged account; detections should baseline normal authenticated HTTP behavior for Simphony users to identify abuse
  • ·No user interaction required and network complexity is low, meaning exploitation can be automated and rapid once credentials are obtained

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_oracle9.9CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.