English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Oracle Siebel CRM Siebel UI Framework Two Vulnerabilities


Secunia ID

SA51002

CVE-ID

CVE-2012-3229, CVE-2012-3230

Release Date

17 Oct 2012

Criticality

Less Critical

Solution Status

Vendor Patch

Software

Oracle Siebel CRM 8.x

Where

From remote

Impact
Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Description

Two vulnerabilities have been reported in Oracle Siebel CRM, which can be exploited by malicious users and malicious people to disclose certain sensitive information.

1) An error within the Portal Framework sub-component of the Siebel UI Framework can be exploited to read certain Siebel UI Framework accessible data.

2) An error within the Siebel Documentation sub-component of the Siebel UI Framework can be exploited to read certain Siebel UI Framework accessible data.

The vulnerabilities are reported in version 8.1.1.

Solution

Apply updates (please see the vendor's advisory for details).
https://support.oracle.com/rs?type=doc&id=1496538.1

Reported by

It is currently unclear who reported the vulnerabilities as the Oracle Critical Patch Update for October 2012 only provides a bundled list of credits. This section will be updated when/if the original reporters provide more information.

Original Advisory

http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html#AppendixSECR
http://www.oracle.com/technetwork/topics/security/cpuoct2012verbose-1515934.html#SECR