Executive brief
A vulnerability exists in the Open UI subcomponent of Oracle Siebel CRM, a platform used for managing customer relationships and business processes. An attacker with low-level access to the system could potentially modify, insert, or delete certain data within the user interface framework. While the exploit is difficult to perform, it could lead to unauthorized changes to business information or system records.
Technical details
This vulnerability affects the Open UI subcomponent of the Oracle Siebel UI Framework, specifically version 16.1. It is classified as a low-severity issue because it is difficult to exploit (High Attack Complexity) and requires the attacker to have at least low-level authenticated privileges. The attack is conducted over the network via HTTP. If successfully exploited, an attacker can gain unauthorized update, insert, or delete access to a subset of data accessible to the Siebel UI Framework. The impact is limited to integrity, with no reported impact on confidentiality or system availability. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Siebel CRM (Siebel UI Framework) 16.1
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update January 2017