OSA-36919674
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: EAI, UI (TinyMCE)). Supported versions that are affected are 24.7-25.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM End User accessible data as well as unauthorized read access to a subset of Siebel CRM End User accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N).
Risk Scores
Timeline
- Apr 21, 2025 CVE Published