cbcvebase.

Oracle Siebel Ui Framework vulnerabilities

53 known vulnerabilities affecting oracle/siebel_ui_framework.

Total CVEs
53
CISA KEV
1
actively exploited
Public exploits
9
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH16MEDIUM28LOW3

Vulnerabilities

Page 3 of 3
CVE-2017-10315P4MEDIUMCVSS 6.1v16.0v17.02017-10-19
CVE-2017-10315 [MEDIUM] CVE-2017-10315: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the
nvd
CVE-2017-10302P4MEDIUMCVSS 6.1v16.0v17.02017-10-19
CVE-2017-10302 [MEDIUM] CVE-2017-10302: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the
nvd
CVE-2019-2857P4MEDIUMCVSS 5.4≤ 19.02019-07-23
CVE-2019-2857 [MEDIUM] CVE-2019-2857: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 19.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the a
nvd
CVE-2016-0673P4MEDIUMCVSS 5.4v8.1.1v8.2.22016-04-21
CVE-2016-0673 [MEDIUM] CVE-2016-0673: Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to UIF Open UI.
nvd
CVE-2016-5450P4MEDIUMCVSS 4.7v8.1.1v8.2.2+3 more2016-07-21
CVE-2016-5450 [MEDIUM] CVE-2016-5450: Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect integrity via vectors related to UIF Open UI.
nvd
CVE-2020-9488P4LOWCVSS 3.7≤ 21.22020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2020-2560P4MEDIUMCVSS 4.7≤ 19.102020-01-15
CVE-2020-2560 [MEDIUM] CVE-2020-2560: Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supp Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supported versions that are affected are 19.10 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the atta
nvd
CVE-2020-2738P4MEDIUMCVSS 4.3≤ 20.22020-04-15
CVE-2020-2738 [MEDIUM] CVE-2020-2738: Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI, SWSE). Suppor Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI, SWSE). Supported versions that are affected are 20.2 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized read access to
nvd
CVE-2018-2959P4MEDIUMCVSS 4.3v18.02018-07-18
CVE-2018-2959 [MEDIUM] CVE-2018-2959: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). The supported version that is affected is 18.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker.
nvd
CVE-2016-5464P4MEDIUMCVSS 4.1v8.1.1v8.2.2+3 more2016-07-21
CVE-2016-5464 [MEDIUM] CVE-2016-5464: Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect integrity via vectors related to SWSE Server, a different vulnerability than CVE-2016-5463.
nvd
CVE-2016-5463P4MEDIUMCVSS 4.1v8.1.1v8.2.2+3 more2016-07-21
CVE-2016-5463 [MEDIUM] CVE-2016-5463: Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect integrity via vectors related to SWSE Server, a different vulnerability than CVE-2016-5464.
nvd
CVE-2017-3264P4LOWCVSS 3.1v16.12017-01-27
CVE-2017-3264 [LOW] CVE-2017-3264: Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Open UI). The Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Open UI). The supported version that is affected is 16.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized update, insert or del
nvd
CVE-2021-1996P4LOWCVSS 2.4≤ 20.122021-01-20
CVE-2021-1996 [LOW] CVE-2021-1996: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a perso
nvd
Oracle Siebel Ui Framework vulnerabilities | cvebase