Oracle Siebel CRM Flaws Let Remote/Local Users Partially Access Data and Remote Users Partially Modify Data
|
SecurityTracker Alert ID: 1030585 |
SecurityTracker URL: http://securitytracker.com/id/1030585
|
CVE Reference:
CVE-2014-2485, CVE-2014-2491, CVE-2014-4205, CVE-2014-4230, CVE-2014-4231, CVE-2014-4250
(Links to External Site)
|
Date: Jul 16 2014
|
Impact:
Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
Several vulnerabilities were reported in Oracle Siebel CRM. A remote user can partially modify data on the target system. A remote or local user can partially access data on the target system.
A local user can exploit a flaw in the Siebel Core - EAI component to partially access data [CVE-2014-2485].
A remote user can exploit a flaw in the Siebel UI Framework component to partially modify data [CVE-2014-2491].
A remote user can exploit a flaw in the Siebel UI Framework component to partially modify data [CVE-2014-4205].
A remote user can exploit a flaw in the Siebel UI Framework component to partially modify data [CVE-2014-4230].
A remote user can exploit a flaw in the Siebel Travel & Transportation component to partially modify data [CVE-2014-4231].
A remote authenticated user can exploit a flaw in the Siebel Core - Server OM Frwks component to partially access data [CVE-2014-4250].
The following researchers reported these and other Oracle vulnerabilities:
Alon Friedman; Andrea Micalizzi aka rgod, working with HP's Zero Day Initiative; Borked of the Google Security Team; CERT/CC; Cihan Oncu; David Litchfield of Datacom TSS; Florian Weimer of Red Hat; Ilja van Sprundel of ioactive.com; Jeroen Frijters;
John Leitch working with HP's Zero Day Initiative; Larry W. Cashdollar; Matt Bergin of KoreLogic Disclosures; Michael Miller of Integrigy; Peter Kamensky of ERPScan (Digital Security Research Group); Rafal Wojtczuk of Bromium;
Rohan Stelling of BAE Systems Detica; Sayan Malakshinov of PSBank; Serguei Mourachov; Toby Clarke of Gotham Digital Science; and Yash Kadakia of Security Brigade.
|
Impact:
A remote user can partially modify data on the target system.
A remote or local user can partially access data on the target system.
|
Solution:
The vendor has issued a fix as part of Oracle Critical Patch Update Advisory - July 2014.
The vendor's advisory is available at:
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
|
Vendor URL: www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html (Links to External Site)
|
Cause:
Not specified
|
Underlying OS: Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|