PT-2015-2799 · Oracle · Oracle Siebel Crm
Published
2015-07-16
·
Updated
2017-09-22
·
CVE-2015-2612
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Siebel CRM versions 8.1.1, 8.2.2, and 15.0
Description
The issue is related to errors in the code of the Siebel Core - Server OM Svcs component in Oracle Siebel CRM, which can be exploited by a remote attacker to compromise the confidentiality of information. The vulnerability is related to vectors associated with the LDAP Security Adapter.
Recommendations
For versions 8.1.1, 8.2.2, and 15.0, consider restricting access to the LDAP Security Adapter as a temporary mitigation measure until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Siebel Crm