SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Oracle Micros Point-Of-Sale Systems Critical Vulnerability (CVE-2018-2636)

Oracle Micros Point-Of-Sale Systems Critical Vulnerability (CVE-2018-2636)

Oracle Micros POS is a hospitality management platform providing enterprise point-of-sale (POS) and back-office functionality to support a wide range of food and beverage operations. Oracle’s MICROS has more than 330,000 cash registers worldwide and currently. Oracle is the third-largest provider of...

Jan 31, 2018By Shakeel Bhat3 min read

Oracle Micros POS is a hospitality management platform providing enterprise point-of-sale (POS) and back-office functionality to support a wide range of food and beverage operations. Oracle’s MICROS has more than 330,000 cash registers worldwide and currently. Oracle is the third-largest provider of PoS software on the market. A good Vulnerability Management Tool can prevent these attacks.

Oracle, in January 2018, as part of their quarterly patching schedule, released a patch for a critical remotely exploitable vulnerability that affects thousands of MICROS point-of-sale (POS). Business solutions worldwide. The flaw has been identified with CVE-2018-2636 and is classified as having a CVSS base score of 8.1 for its severity. The flaw allows anyone accessing the device to conduct a directory traversal attack. If exploited, the flaw will allow unauthenticated users to access sensitive data and receive information about various services from vulnerable MICROS workstations. Attackers can read service logs and configuration files on vulnerable devices. Attackers can get hold of customer names, email addresses, user’sdate of birth, phone numbers, total sales, debit and creditcards, and information about different promotions and discounts. In addition, attackers can alter these details as well. Vulnerability Management Software is the solution for these issues.

Micros POS:

Oracle Micros POS devices store usernames and encrypted passwords for connecting to the database in SimphonyInstall.xml or Dbconfix.xml files. Using a directory traversal attack, an attacker can gain access to these files and thus get information, including DB usernames and password hashes. Which can then be used to grant attackers full and legitimate access to the POS system. Upon gaining access, an attacker can potentially do anything with the POS system, like installing malware to collect payment card details. A POC is also available, which tries to get the contents of sensitive files from the device.

The flaw can be exploited remotely or from the local network. A number of misconfiguration POS systems are available online and be in exploitation if they are updating with Oracle’s latest patches. Many POS systems may be properly in configuration and inaccessible over the Internet but are also vulnerable. However, Attackers can compromise other systems on the store’s internal network and use them as control points for the attack code. An attacker can always visit the store, find digital scales or any other device that uses RJ45, and connect it to Raspberry PI. Scan the internal network, and run the malicious exploit code.

Although Oracle issued updates for this issue earlier in January 2018, it will take months until the affection devices are patching as the POS systems. Are business-critical systems and system administrators rarely schedule update operations? Fearing downtime and financial losses to their companies in an unstable patch. Moreover, being business-critical and always busy, POS systems are not updating immediately.

Exploitation:

Below is an example showing the response of a malicious request to read micros db i.e., usernames and hashes. The vulnerable MICROS server sends back a special response with the details intended.

Affected versions of Oracle Micros Point-Of-Sale Systems:

All the currently supports versions 2.7, 2.8, and 2.9 are in effect.

Solution:

Therefore, Apply the latest patch released by Oracle earlier in January 2018 patch update. In addition to this. Oracle’s January 2018 patch update includes fixes for Spectre and Meltdown Intel processor vulnerabilities affecting certain Oracle products.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026