Vulnerability in Oracle Siebel CRM's Server BizLogic Script Component
CVE-2021-2004
4.3MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2021
What is CVE-2021-2004?
A vulnerability exists in the Server BizLogic Script component of Oracle Siebel CRM, which affects versions 20.12 and earlier. This flaw allows a low-privileged attacker to exploit the system remotely via HTTP, potentially leading to unauthorized read access to sensitive information contained within the Siebel Core. The vulnerability presents a significant risk by enabling attackers to access data that should otherwise be restricted, compromising the integrity and confidentiality of the system. Organizations utilizing impacted versions should evaluate their systems and apply relevant patches to mitigate the risk.
Affected Version(s)
Siebel Core - Server Framework 20.12 and prior