PT-2021-7140 · Oracle · Siebel Core-Server Framework

Published

2021-07-20

·

Updated

2021-07-23

·

CVE-2021-2353

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Siebel Core - Server Framework versions 21.5 and Prior
Description The issue exists due to insufficient input validation in the Loging component of the Siebel Core - Server Framework product of Oracle Siebel CRM. This can allow an attacker to gain unauthorized access to protected information using the HTTP protocol. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data.
Recommendations For versions 21.5 and Prior, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03458
CVE-2021-2353

Affected Products

Siebel Core-Server Framework