Unauthorized Access Vulnerability in Oracle Siebel CRM SWSE Server
CVE-2020-14531
5.9MEDIUM
What is CVE-2020-14531?
This vulnerability in the Oracle Siebel CRM's SWSE Server component enables an unauthenticated attacker with HTTP network access to potentially compromise the Siebel UI Framework. Exploiting this vulnerability requires user interaction from someone other than the attacker, making it particularly difficult to orchestrate. If successfully exploited, the attacker may gain unauthorized access to sensitive data and possess the ability to perform updates, additions, or deletions to available data within the Siebel UI Framework, thereby compromising the confidentiality and integrity of the system.
Affected Version(s)
Siebel UI Framework 20.6 and prior