CVE-2018-3059 is a vulnerability in the Siebel UI Framework component of Oracle Siebel CRM, specifically affecting versions 18.7, 18.8, and 18.9. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the Siebel UI Framework. Successful attacks require user interaction and can lead to unauthorized read, update, insert, or delete access to a subset of Siebel UI Framework accessible data. The vulnerability has a CVSS 3.0 Base Score of 6.1 (Medium), indicating moderate severity. Its attack vector is network-based with low attack complexity, but it requires user interaction (UI:R). The scope is changed (S:C), meaning the attack can impact additional products beyond the vulnerable component, resulting in partial confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, nor is there any known exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.7CPE matchmatch criteria | cpe:2.3:a:oracle:siebel_ui_framework:18.7:*:*:*:*:*:*:* | ||
18.8CPE matchmatch criteria | cpe:2.3:a:oracle:siebel_ui_framework:18.8:*:*:*:*:*:*:* | ||
18.9CPE matchmatch criteria | cpe:2.3:a:oracle:siebel_ui_framework:18.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.