PT-2021-7140 · Oracle · Siebel Core-Server Framework
Published
2021-07-20
·
Updated
2021-07-23
·
CVE-2021-2353
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Siebel Core - Server Framework versions 21.5 and Prior
Description
The issue exists due to insufficient input validation in the Loging component of the Siebel Core - Server Framework product of Oracle Siebel CRM. This can allow an attacker to gain unauthorized access to protected information using the HTTP protocol. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data.
Recommendations
For versions 21.5 and Prior, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siebel Core-Server Framework