Junglewise Threat Intelligence

CVE-2017-3325: Oracle Siebel CRM data compromise in Siebel UI Framework EAI

CVE-2017-3325 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Siebel Ui Framework. Vendors: Oracle.

Executive brief

A vulnerability exists in the Enterprise Application Integration (EAI) subcomponent of Oracle Siebel CRM. This flaw allows an unauthenticated remote attacker to trick a legitimate user into performing an action that grants the attacker unauthorized access to sensitive business data. If successfully exploited, an attacker could view, modify, or delete critical information within the Siebel UI Framework, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the Siebel UI Framework (specifically the EAI subcomponent) in Oracle Siebel CRM version 16.1. It is an easily exploitable flaw that can be triggered by an unauthenticated attacker over the network via HTTP. Exploitation requires human interaction from a person other than the attacker (UI:R), suggesting a cross-site scripting (XSS) or request forgery style vector. A successful attack has a high impact on confidentiality and a low impact on integrity, with a scope change (S:C) indicating that the compromise can extend beyond the Siebel UI Framework to other integrated products. Attackers can achieve unauthorized access to all accessible data or perform unauthorized updates and deletions of certain records.

Affected products

  • Oracle Siebel UI Framework 16.1

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017

References

Related threats