CVE-2017-10300

MEDIUM

Oracle Siebel CRM Desktop 16.0 and 17.0 - Unauthenticated Exposure of Sensitive Information via HTTP

Title source: llm
STIX 2.1

Description

Vulnerability in the Siebel CRM Desktop component of Oracle Siebel CRM (subcomponent: Siebel Business Service Issues). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Desktop. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Desktop accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101400

Scores

CVSS v3 5.3
EPSS 0.0051
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (4)
oracle/siebel_customer_relationship_management_desktop 16.0
oracle/siebel_customer_relationship_management_desktop 17.0
Oracle Corporation/Siebel CRM Desktop 16.0
Oracle Corporation/Siebel CRM Desktop 17.0
Published Oct 19, 2017
Tracked Since Feb 18, 2026