Unauthenticated Access Vulnerability in Oracle Siebel CRM Web Applications
CVE-2019-2719

6.1MEDIUM

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
23 April 2019

Summary

The vulnerability in Oracle Knowledge within Oracle Siebel CRM allows an unauthenticated attacker with network access via HTTP to compromise sensitive data. Exploitation of this vulnerability may result in unauthorized update, insertion, or deletion of accessible data, as well as unauthorized read access to a subset of this data. While the vulnerability is specifically in the Oracle Knowledge component, successful attacks could significantly impact other products within the Oracle Siebel CRM suite. Notably, human interaction from an individual other than the attacker is required for successful exploitation, highlighting the potential for social engineering tactics in these attacks.

Affected Version(s)

Knowledge 8.5.1.0 - 8.5.1.7

Knowledge 8.6.0

Knowledge 8.6.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.