Vulnerability in Oracle Siebel CRM Server Framework
CVE-2018-2789

5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2018

Summary

An improper access control vulnerability exists in the Server Framework component of Oracle's Siebel CRM. This flaw allows an unauthorized, low-privileged attacker with network access via HTTP to potentially compromise the Server Framework, leading to unauthorized read access to sensitive data. While primarily affecting the Server Framework, the implications of this vulnerability may extend to other interrelated components, necessitating immediate attention to ensure data security and integrity.

Affected Version(s)

Siebel Core - Server Framework 17.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.