Junglewise Threat Intelligence

CVE-2017-3330: Oracle Siebel CRM vulnerability in Siebel UI Framework Open UI

CVE-2017-3330 · Severity: high · CVSS 7.6 · Published 2017-01-27

Technologies: Oracle Siebel CRM, Oracle Siebel Ui Framework. Vendors: Oracle.

Executive brief

A vulnerability exists in the Open UI component of Oracle Siebel CRM, a platform used by businesses to manage customer relationships and data. An attacker with basic user access could exploit this flaw to view, modify, or delete sensitive customer information. This attack requires a legitimate user to interact with a malicious link or page, and the impact could extend beyond the Siebel system to other integrated business applications.

Technical details

This vulnerability affects the Siebel UI Framework (specifically the Open UI subcomponent) in Oracle Siebel CRM version 16.1. It is classified as an 'Insufficient Information' (NVD-CWE-noinfo) issue, but the CVSS vector suggests a cross-site flaw or similar injection where a low-privileged attacker can leverage network access via HTTP. The exploit requires human interaction from a victim (UI:R) and results in a Scope change (S:C), meaning the attack can impact components outside the immediate security scope of the Siebel UI. Successful exploitation allows for unauthorized access to critical data (Confidentiality: High) and unauthorized update, insert, or delete capabilities (Integrity: Low). Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Siebel CRM 16.1

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats