Executive brief
A vulnerability exists in the Enterprise Application Integration (EAI) subcomponent of Oracle Siebel CRM. This flaw allows an unauthenticated remote attacker to trick a legitimate user into performing an action that grants the attacker unauthorized access to sensitive business data. If successfully exploited, an attacker could view, modify, or delete critical information within the Siebel UI Framework, potentially impacting other integrated business systems.
Technical details
This vulnerability affects the Siebel UI Framework (specifically the EAI subcomponent) in Oracle Siebel CRM version 16.1. It is an easily exploitable flaw that can be triggered by an unauthenticated attacker over the network via HTTP. Exploitation requires human interaction from a person other than the attacker (UI:R), suggesting a cross-site scripting (XSS) or request forgery style vector. A successful attack has a high impact on confidentiality and a low impact on integrity, with a scope change (S:C) indicating that the compromise can extend beyond the Siebel UI Framework to other integrated products. Attackers can achieve unauthorized access to all accessible data or perform unauthorized updates and deletions of certain records.
Affected products
- Oracle Siebel UI Framework 16.1
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017