PT-2015-2799 · Oracle · Oracle Siebel Crm

Published

2015-07-16

·

Updated

2017-09-22

·

CVE-2015-2612

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Siebel CRM versions 8.1.1, 8.2.2, and 15.0
Description The issue is related to errors in the code of the Siebel Core - Server OM Svcs component in Oracle Siebel CRM, which can be exploited by a remote attacker to compromise the confidentiality of information. The vulnerability is related to vectors associated with the LDAP Security Adapter.
Recommendations For versions 8.1.1, 8.2.2, and 15.0, consider restricting access to the LDAP Security Adapter as a temporary mitigation measure until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12164
CVE-2015-2612

Affected Products

Oracle Siebel Crm