Siebel Critical Patch Update for July 2014 Now Available
The July 2014 Critical Patch Update is now available and is packaged with Patchset 9 on both Siebel 8.1.1.11 and 8.2.2.4.
Critical Patch Updates are released quarterly to address potential or discovered security vulnerabilities within the Siebel application. As such, customers are strongly encouraged to apply these Critical Patch Updates as soon as possible to their environments.
The July 2014 Critical Patch Update contains several Siebel related items:
CVE-2014-4231 Vulnerability in the Siebel Travel & Transportation component of Oracle Siebel CRM (subcomponent: Diary). Supported versions that are affected are 8.1.1 and 8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Siebel Travel & Transportation accessible data. CVSS Base Score 4.3 (Integrity impacts). CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).