Server BizLogic Script Vulnerability in Oracle Siebel CRM
CVE-2019-2570

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 April 2019

Summary

A vulnerability exists in the Oracle Siebel CRM's Server BizLogic Script component, specifically within the Integration - Scripting subcomponent. This issue can be easily exploited by an authenticated attacker with network access via HTTP. Successful exploitation permits unauthorized manipulation of accessible data, including the ability to update, insert, or delete entries. Additionally, it may allow unauthorized read access to specific data and could result in a partial denial of service to the affected components.

Affected Version(s)

Siebel Core - Server Framework 19.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.