Oracle Siebel Core CVE-2010-2406 Remote Siebel Core - Highly Interactive Client Vulnerabilities
BID:44049
Info
Oracle Siebel Core CVE-2010-2406 Remote Siebel Core - Highly Interactive Client Vulnerabilities
| Bugtraq ID: | 44049 |
| Class: | Unknown |
| CVE: |
CVE-2010-2406 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2010 12:00AM |
| Updated: | Oct 19 2010 03:39PM |
| Credit: | Roberto Suggi Liverani from Security-Assessment.com |
| Vulnerable: |
Oracle Siebel 8.1 Oracle Siebel 8.0 Oracle Siebel 7.8 Oracle Siebel 7.7 |
| Not Vulnerable: | |
Discussion
Oracle Siebel Core CVE-2010-2406 Remote Siebel Core - Highly Interactive Client Vulnerabilities
Oracle Siebel Core is prone to multiple remote cross-site scripting vulnerabilities in Siebel Core - Highly Interactive Client.
The vulnerabilities can be exploited over the 'HTTP' protocol. An attacker does not require privileges to exploit these vulnerabilities.
These vulnerabilities affects the following supported versions:
7.7.2.12, 7.8.2.14, 8.0.0.10, 8.1.1.3
Oracle Siebel Core is prone to multiple remote cross-site scripting vulnerabilities in Siebel Core - Highly Interactive Client.
The vulnerabilities can be exploited over the 'HTTP' protocol. An attacker does not require privileges to exploit these vulnerabilities.
These vulnerabilities affects the following supported versions:
7.7.2.12, 7.8.2.14, 8.0.0.10, 8.1.1.3
Exploit / POC
Oracle Siebel Core CVE-2010-2406 Remote Siebel Core - Highly Interactive Client Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user into following a specially crafted URI.
The following example URIs are available:
To exploit these issues, an attacker must entice an unsuspecting user into following a specially crafted URI.
The following example URIs are available:
Solution / Fix
Oracle Siebel Core CVE-2010-2406 Remote Siebel Core - Highly Interactive Client Vulnerabilities
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Siebel Core CVE-2010-2406 Remote Siebel Core - Highly Interactive Client Vulnerabilities
References:
References:
- Oracle Siebel eBusiness Application �?? Multiple Cross Site Scripting Vulnerabilit (Roberto Suggi Liverani)
- Oracle Critical Patch Update Advisory - October 2010 (Oracle)