Cross-site Scripting Flaw in Oracle Siebel Core Components
CVE-2019-2779
4.2MEDIUM
Summary
A cross-site scripting vulnerability exists in the Email component of Oracle Siebel CRM. This flaw allows an attacker with elevated privileges and network access via HTTP to potentially compromise the Siebel Core - Common Components. Exploitation necessitates user interaction, meaning that an unsuspecting individual must engage with the attacker’s crafted link. If successfully exploited, this vulnerability can lead to unauthorized access to sensitive data and may grant the attacker complete access to all information stored within the affected Siebel Core components.
Affected Version(s)
Siebel Core - Common Components 19.0 and prior
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved