First published: Tue Apr 18 2023(Updated: )
Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: UI Framework). Supported versions that are affected are 23.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Siebel CRM | <=23.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21909 is rated as easily exploitable, posing a low but significant risk to affected systems.
CVE-2023-21909 affects Oracle Siebel CRM versions 23.3 and earlier.
To mitigate CVE-2023-21909, upgrade Oracle Siebel CRM to a version beyond 23.3 that contains the necessary security fixes.
Yes, CVE-2023-21909 can be exploited by a low privileged attacker with network access via HTTP.
CVE-2023-21909 affects the UI Framework component of the Oracle Siebel CRM product.