CVE-2025-30758

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface). Supported versions that are affected are 25.0-25.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM End User accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
References
Link Resource
https://www.oracle.com/security-alerts/cpujul2025.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*

History

29 Jul 2025, 17:35

Type Values Removed Values Added
References () https://www.oracle.com/security-alerts/cpujul2025.html - () https://www.oracle.com/security-alerts/cpujul2025.html - Patch, Vendor Advisory
CPE cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
First Time Oracle siebel Crm Deployment
Oracle

16 Jul 2025, 15:15

Type Values Removed Values Added
CWE CWE-200

16 Jul 2025, 14:59

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad en el producto Siebel CRM End User de Oracle Siebel CRM (componente: Interfaz de Usuario). Las versiones compatibles afectadas son las 25.0-25.5. Esta vulnerabilidad, fácilmente explotable, permite a un atacante no autenticado con acceso a la red vía HTTP comprometer la seguridad de Siebel CRM End User. Los ataques con éxito de esta vulnerabilidad pueden resultar en acceso de lectura no autorizado a un subconjunto de datos accesibles para Siebel CRM End User. Puntuación base de CVSS 3.1: 5.3 (Afecta a la confidencialidad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

15 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-15 20:15

Updated : 2025-07-29 17:35


NVD link : CVE-2025-30758

Mitre link : CVE-2025-30758

CVE.ORG link : CVE-2025-30758


JSON object : View

Products Affected

oracle

  • siebel_crm_deployment
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor