cbcvebase.

Oracle Siebel Ui Framework vulnerabilities

53 known vulnerabilities affecting oracle/siebel_ui_framework.

Total CVEs
53
CISA KEV
1
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH16MEDIUM28LOW3

Vulnerabilities

Page 2 of 3
CVE-2021-2351P3HIGHCVSS 7.5≤ 21.122021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2016-5451P3HIGHCVSS 8.1v8.1.1v8.2.2+3 more2016-07-21
CVE-2016-5451 [HIGH] CVE-2016-5451: Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality and integrity via vectors related to EAI, a different vulnerability than CVE-2016-5468.
nvd
CVE-2017-3325P3HIGHCVSS 8.2v16.12017-01-27
CVE-2017-3325 [HIGH] CVE-2017-3325: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI). The sup Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI). The supported version that is affected is 16.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker and while
nvd
CVE-2021-25329P3HIGHCVSS 7.0fixed in 21.9v21.92021-03-01
CVE-2021-25329 [HIGH] CVE-2021-25329: The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously
nvd
CVE-2017-10263P3HIGHCVSS 8.2v16.0v17.02017-10-19
CVE-2017-10263 [HIGH] CVE-2017-10263: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the a
nvd
CVE-2016-7103P3MEDIUMCVSS 6.1≤ 21.22017-03-15
CVE-2016-7103 [MEDIUM] CWE-79 CVE-2016-7103: Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
nvd
CVE-2017-10333P3HIGHCVSS 7.4v16.0v17.02017-10-19
CVE-2017-10333 [HIGH] CVE-2017-10333: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI). Support Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework. While the vulnerability is in Siebel UI Framework, attacks may significantly impact
nvd
CVE-2017-3330P3HIGHCVSS 7.6v16.12017-01-27
CVE-2017-3330 [HIGH] CVE-2017-3330: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Open UI). The Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Open UI). The supported version that is affected is 16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker and whi
nvd
CVE-2018-8032P4MEDIUMCVSS 6.1≤ 21.02018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2021-26272P4MEDIUMCVSS 6.5≤ 21.92021-01-26
CVE-2021-26272 [MEDIUM] CWE-829 CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8≤ 20.52020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2021-26271P4MEDIUMCVSS 6.5fixed in 21.92021-01-26
CVE-2021-26271 [MEDIUM] CWE-829 CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
nvd
CVE-2020-14531P4MEDIUMCVSS 5.9≤ 20.62020-07-15
CVE-2020-14531 [MEDIUM] CVE-2020-14531: Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supp Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supported versions that are affected are 20.6 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the a
nvd
CVE-2020-2559P4MEDIUMCVSS 5.3≤ 19.72020-01-15
CVE-2020-2559 [MEDIUM] CVE-2020-2559: Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: UIF Open UI). Supp Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: UIF Open UI). Supported versions that are affected are 19.7 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2020-2564P4MEDIUMCVSS 5.3≤ 19.102020-01-15
CVE-2020-2564 [MEDIUM] CVE-2020-2564: Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported ve Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 19.10 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized read access to a s
nvd
CVE-2019-2935P4MEDIUMCVSS 5.3≤ 19.82019-10-16
CVE-2019-2935 [MEDIUM] CVE-2019-2935: Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported ve Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 19.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized read access to a su
nvd
CVE-2016-5468P4MEDIUMCVSS 5.4v8.1.1v8.2.2+3 more2016-07-21
CVE-2016-5468 [MEDIUM] CVE-2016-5468: Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality and integrity via vectors related to EAI, a different vulnerability than CVE-2016-5451.
nvd
CVE-2017-10264P4MEDIUMCVSS 5.3v16.0v17.02017-10-19
CVE-2017-10264 [MEDIUM] CVE-2017-10264: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2021-32808P4MEDIUMCVSS 5.4≤ 21.92021-08-12
CVE-2021-32808 [MEDIUM] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEdit
nvd
CVE-2018-3059P4MEDIUMCVSS 6.1v18.7v18.8+1 more2018-10-17
CVE-2018-3059 [MEDIUM] CVE-2018-3059: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 18.7, 18.8 and 18.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than
nvd