Vulnerability in Oracle Siebel CRM's Server Framework Component
CVE-2017-10162

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

A weakness exists in the Siebel Core - Server Framework component of Oracle Siebel CRM, specifically in versions 16.0 and 17.0. An attacker with low-level privileges can exploit this flaw through network access via HTTP, allowing unauthorized actions such as updates, inserts, or deletions to accessible data. Additionally, there is potential for unauthorized read access to certain data within the Server Framework, putting the confidentiality and integrity of the data at risk.

Affected Version(s)

Siebel Core - Server Framework 16.0

Siebel Core - Server Framework 17.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.