Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel UI Framework. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
References
Link | Resource |
---|---|
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/101411 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-10-19 10:29
Updated : 2017-10-24 09:36
NVD link : CVE-2017-10264
Mitre link : CVE-2017-10264
JSON object : View
CWE
Products Affected
oracle
- siebel_ui_framework