Cross-site Scripting Flaw in Oracle Siebel Core Components
CVE-2019-2779

4.2MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

A cross-site scripting vulnerability exists in the Email component of Oracle Siebel CRM. This flaw allows an attacker with elevated privileges and network access via HTTP to potentially compromise the Siebel Core - Common Components. Exploitation necessitates user interaction, meaning that an unsuspecting individual must engage with the attacker’s crafted link. If successfully exploited, this vulnerability can lead to unauthorized access to sensitive data and may grant the attacker complete access to all information stored within the affected Siebel Core components.

Affected Version(s)

Siebel Core - Common Components 19.0 and prior

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.