Siebel Core Server Framework

Vendor:

First CVE: Jul 21, 2016 · Active for 10 years

16
Total CVEs
More Total CVEs than 88% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 5% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Siebel Core Server Framework over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2016
10 years ago
Most Recent CVE
Jul 21, 2021
1,829 days ago

CVE Severity & Scoring

Siebel Core Server Framework16 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local2 (12.5%)
Network14 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (62.5%)
High6 (37.5%)
Unknown0 (0.0%)
User Interaction
None13 (81.3%)
Unknown0 (0.0%)
Required3 (18.8%)
Privileges Required
Low6 (37.5%)
High2 (12.5%)
None8 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfigur
Sep 17, 20208.129NONO
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream
Apr 7, 20207.529NONO
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requ
May 23, 20195.925NONO
Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Search). Supported versions that are affected are 20.12 and prior. Easily exploitable v
Jan 20, 20217.623NONO
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect
Jul 21, 20166.522NONO
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect
Jul 21, 20165.320NONO
Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Loging). Supported versions that are affected are 21.5 and Prior. Easily exploitable vu
Jul 21, 20214.418NONO
Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services). The supported version that is affected is 17.0. Easily exploitable vuln
Apr 19, 20185.018NONO
Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services). Supported versions that are affected are 16.0 and 17.0. Easily exploita
Oct 19, 20175.418NONO
Vulnerability in the Siebel Core CRM component of Oracle Siebel CRM (subcomponent: Search). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability
Aug 8, 20176.118NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Siebel Core Server Framework

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.2.274.11.7%00
8.1.174.11.7%00
201674.11.7%00
201574.11.7%00
201474.11.7%00
17.035.51.1%00
16.025.81.1%00