CVE-2023-21909: Medium severity oracle siebel core - common components vulnerability
Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: UI Framework). Supported versions that are affected are 23.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21909?
CVE-2023-21909 is rated as easily exploitable, posing a low but significant risk to affected systems.
What versions are affected by CVE-2023-21909?
CVE-2023-21909 affects Oracle Siebel CRM versions 23.3 and earlier.
How do I fix CVE-2023-21909?
To mitigate CVE-2023-21909, upgrade Oracle Siebel CRM to a version beyond 23.3 that contains the necessary security fixes.
Can a low privileged attacker exploit CVE-2023-21909?
Yes, CVE-2023-21909 can be exploited by a low privileged attacker with network access via HTTP.
What component of Oracle Siebel CRM is affected by CVE-2023-21909?
CVE-2023-21909 affects the UI Framework component of the Oracle Siebel CRM product.