Vulnerability in Oracle Siebel CRM's Installer and Deployment Component
CVE-2018-2632

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

This vulnerability allows a low privileged attacker with network access via HTTP to compromise the Installer and Deployment component of Oracle Siebel CRM, specifically targeting the Siebel Approval Manager. As a result, unauthorized read access to specific data sets may occur, potentially exposing sensitive information to attackers. This situation underscores the importance of ensuring updated security measures and addressing vulnerabilities promptly.

Affected Version(s)

Siebel Engineering - Installer and Deployment 16.0

Siebel Engineering - Installer and Deployment 17.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.