CVE-2024-21010
published 2024-04-16CVE-2024-21010: Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions…
PriorityP261critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.73%
50.1th percentile
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | hospitality_simphony | 19.1.0 – 19.5.4 | — |
| oracle_corporation | hospitality_simphony | 19.1.0 – 19.5.4 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability targets Oracle Hospitality Simphony Enterprise Server component via HTTP with low-privilege network access; monitor for anomalous HTTP requests from authenticated low-privileged users against Simphony Enterprise Server endpoints ↗
- →Scope change is indicated — successful exploitation may pivot to additional products beyond Simphony itself; monitor lateral movement from Simphony Enterprise Server hosts ↗
- →Affected versions are 19.1.0 through 19.5.4; prioritize detection and patching on hosts running these specific Simphony Enterprise Server versions ↗
- ·No authentication bypass — attacker requires a low-privileged account; detections should baseline normal authenticated HTTP behavior for Simphony users to identify abuse ↗
- ·No user interaction required and network complexity is low, meaning exploitation can be automated and rapid once credentials are obtained ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_oracle9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Enterprise Server — CVE-2024-21010
vendor_oracle·2024-04-15·CVSS 9.9
CVE-2024-21010 [CRITICAL] Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Enterprise Server — CVE-2024-21010
Oracle Oracle Food and Beverage Applications Risk Matrix: Simphony Enterprise Server vulnerability
CVE: CVE-2024-21010
CVSS: 9.9
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
GHSA
GHSA-jp94-w382-qgwr: Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server)
ghsa_unreviewed·2024-04-17
CVE-2024-21010 [CRITICAL] CWE-863 GHSA-jp94-w382-qgwr: Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server)
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-16
Published