Exploitable Vulnerability in Oracle Siebel CRM's UI Framework
CVE-2019-2857
5.4MEDIUM
Summary
This vulnerability in the Siebel UI Framework component of Oracle Siebel CRM allows a low-privileged attacker with network access via HTTP to compromise the framework. While the attack requires human interaction, it can lead to unauthorized changes and access to data. Affected users may face significant risks to data confidentiality and integrity as attackers can execute unauthorized updates, insertions, and deletions of accessible data. The exploitation of this issue could potentially impact a broader set of connected products.
Affected Version(s)
Siebel UI Framework 19.0 and prior
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved