Risk | High |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2021-29425 CVE-2021-30639 CVE-2021-23926 |
CWE-ID | CWE-22 CWE-755 CWE-776 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Siebel Apps - Marketing Web applications / CRM systems |
Vendor | Oracle |
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU52252
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-29425
CWE-ID:
CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error within the FileNameUtils.normalize method when processing directory traversal sequences, such as "//../foo", or "\..foo". A remote attacker can send a specially crafted request and verify files availability in the parent folder.
Install update from vendor's website.
Vulnerable software versionsSiebel Apps - Marketing: 22.0 - 22.8
http://www.oracle.com/security-alerts/cpuoct2022.html?917636
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU55422
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-30639
CWE-ID:
CWE-755 - Improper Handling of Exceptional Conditions
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error management within the application when handling unexpected connection termination. A remote attacker can drop connection with the Apache Tomcat server, which triggers a non-blocking I/O error and causes all requests, handled by that request object, to fail. As a result, a remote attacker can initiate and drop connections to the server and perform a denial of service attack. MitigationInstall update from vendor's website.
Vulnerable software versionsSiebel Apps - Marketing: 22.0 - 22.8
http://www.oracle.com/security-alerts/cpuoct2022.html?917636
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU49517
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-23926
CWE-ID:
CWE-776 - Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation when processing XML data. A remote attacker can pass specially crafted XML data to the application and perform XML Entity Expansion attacks.
Install update from vendor's website.
Vulnerable software versionsSiebel Apps - Marketing: 22.0 - 22.8
http://www.oracle.com/security-alerts/cpuoct2022.html?917636
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?