Authorization Bypass in Oracle Siebel CRM Server Framework
CVE-2021-2353

4.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 July 2021

Summary

This vulnerability in Oracle Siebel CRM's Server Framework enables an attacker with high privileges, who is logged into the environment, to compromise the framework. Successful exploitation may lead to unauthorized access to sensitive data, potentially giving access to all data that the Server Framework can reach. Organizations utilizing affected versions of Oracle Siebel CRM should promptly apply available patches to secure their systems.

Affected Version(s)

Siebel Core - Server Framework 21.5 and Prior

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.