First published: Thu Oct 19 2017(Updated: )
Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel UI Framework. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Siebel User Interface Framework | =16.0 | |
Oracle Siebel User Interface Framework | =17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10264 is classified as a critical vulnerability due to its potential for exploitation by unauthenticated attackers.
To fix CVE-2017-10264, update to the latest version of Oracle Siebel UI Framework beyond the affected versions 16.0 and 17.0.
CVE-2017-10264 affects users of Oracle Siebel UI Framework version 16.0 and 17.0.
CVE-2017-10264 allows unauthenticated attackers with network access via HTTP to compromise the Siebel UI Framework.
The primary component affected by CVE-2017-10264 is the Siebel UI Framework within Oracle Siebel CRM.