Lucene search

K
cveOracleCVE-2017-10264
HistoryOct 19, 2017 - 5:29 p.m.

CVE-2017-10264

2017-10-1917:29:01
oracle
web.nvd.nist.gov
43
cve-2017-10264
oracle
siebel crm
vulnerability
uif open ui
http
network access
denial of service
cvss 3.0

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

27.9%

Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel UI Framework. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Affected configurations

Nvd
Vulners
Node
oraclesiebel_ui_frameworkMatch16.0
OR
oraclesiebel_ui_frameworkMatch17.0
VendorProductVersionCPE
oraclesiebel_ui_framework16.0cpe:2.3:a:oracle:siebel_ui_framework:16.0:*:*:*:*:*:*:*
oraclesiebel_ui_framework17.0cpe:2.3:a:oracle:siebel_ui_framework:17.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Siebel UI Framework",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "16.0"
      },
      {
        "status": "affected",
        "version": "17.0"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

27.9%

Related for CVE-2017-10264