Vulnerability in Oracle Siebel CRM's UI Framework Component
CVE-2017-10333
7.4HIGH
Summary
The vulnerability in Oracle Siebel CRM's UI Framework allows attackers with low privilege levels and network access via HTTP to exploit the system. Attackers can manipulate accessible data stored within the framework, including the ability to unauthorizedly update, insert, or delete records, as well as gain unauthorized read access to sensitive information. This vulnerability can also lead to partial denial of service challenges for the affected components. The supported versions experiencing this issue include 16.0 and 17.0.
Affected Version(s)
Siebel UI Framework 16.0
Siebel UI Framework 17.0
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved