Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: UI Framework). Supported versions that are affected are 23.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.oracle.com/security-alerts/cpuapr2023.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: oracle
Published: 2023-04-18T19:54:16.579Z
Updated: 2024-09-16T19:45:23.029Z
Reserved: 2022-12-17T19:26:00.713Z
Link: CVE-2023-21909
Vulnrichment
Updated: 2024-08-02T09:51:51.463Z
NVD
Status : Modified
Published: 2023-04-18T20:15:12.430
Modified: 2024-11-21T07:43:53.317
Link: CVE-2023-21909
Redhat
No data.