Unauthorized Access Vulnerability in Oracle Siebel CRM SWSE Server
CVE-2020-14531

5.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

This vulnerability in the Oracle Siebel CRM's SWSE Server component enables an unauthenticated attacker with HTTP network access to potentially compromise the Siebel UI Framework. Exploiting this vulnerability requires user interaction from someone other than the attacker, making it particularly difficult to orchestrate. If successfully exploited, the attacker may gain unauthorized access to sensitive data and possess the ability to perform updates, additions, or deletions to available data within the Siebel UI Framework, thereby compromising the confidentiality and integrity of the system.

Affected Version(s)

Siebel UI Framework 20.6 and prior

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.