PT-2026-51422 · Gnu+5 · Debian+7

CVE-2026-47016

·

Published

2026-03-24

·

Updated

2026-07-21

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Oracle Siebel CRM Integration versions 17.0 through 26.4 Mozilla Firefox (affected versions not specified) Mozilla Firefox ESR (affected versions not specified) Thunderbird (affected versions not specified)
Description A vulnerability in the Event Publish and Subscribe component of Oracle Siebel CRM Integration allows an attacker with physical access to gain unauthorized read access to a subset of accessible data. This issue may significantly impact additional products due to a scope change. Separately, a vulnerability in the JavaScript Engine used by Mozilla Firefox, Firefox ESR, and Thunderbird involves the use of an uninitialized resource, which could allow a remote attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08517
CVE-2026-47016

Affected Products

Debian
Firefox
Firefox Esr
Red Hat
Siebel Crm Integration
Thunderbird
Ubuntu
Red Os