Siebel Ui Framework

Vendor:

First CVE: Apr 21, 2016 · Active for 10 years

53
Total CVEs
More Total CVEs than 98% of tracked products
8.8
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
1.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Siebel Ui Framework over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 21, 2016
10 years ago
Most Recent CVE
Dec 28, 2021
1,669 days ago

CVE Severity & Scoring

Siebel Ui Framework53 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (3.8%)
Network50 (94.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.9%)
Attack Complexity
Low41 (77.4%)
High12 (22.6%)
Unknown0 (0.0%)
User Interaction
None29 (54.7%)
Unknown0 (0.0%)
Required24 (45.3%)
Privileges Required
Low13 (24.5%)
High2 (3.8%)
None38 (71.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.582NOYES
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl
Jul 14, 20207.577NOYES
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses
Dec 28, 20216.676NONO
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f
May 20, 20207.066NOYES
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a su
Jul 14, 20207.560NONO

Exploit Exposure

Signals from CVEs in this product scope (53 CVEs).

CISA KEV
1 CVE
1.9% of CVEs· 96th percentile
Metasploit
1 CVE
1.9% of CVEs· 96th percentile
Nuclei
4 CVEs
7.5% of CVEs· 97th percentile
ExploitDB
4 CVEs
7.5% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (53 CVEs).

Media Mentions

Signals from CVEs in this product scope (53 CVEs).

Top CNAs Publishing CVEs For Siebel Ui Framework

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.2.265.31.5%00
8.1.165.31.5%00
21.917.09.5%00
21.1216.697.9%00
20.826.195.1%02
20.619.85.7%00
201655.31.7%00
201555.31.7%00
201455.31.7%00
18.928.045.1%01
18.828.045.1%01
18.728.045.1%01
18.1116.129.7%00
18.1016.129.7%00
18.014.31.2%00
17.056.61.2%00
16.136.31.3%00
16.056.61.2%00