Quarterly Critical Patch Update Now Available for Siebel 8.1 / 8.2
The April 2014 Critical Patch Update was delayed for a month due to unrelated issues with Patchset 6. It is included as part of Patchset 7 on both 8.1.1.11 and 8.2.2.4 released in early May.
Critical Patch Updates are released quarterly to address potential or discovered security vulnerabilities within the Siebel application. As such, customers are strongly encouraged to apply these Critical Patch Updates as soon as possible to their environments.
The April 2014 Critical Patch Update contains one Siebel related item:
CVE-2014-2468 Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Open_UI.). The supported version that is affected is 8.1.1 8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Siebel UI Framework accessible data. CVSS Base Score 4.3 (Integrity impacts).