Siebel System Admin, Install and Upgrade (MOSC)

MOSC Banner

Oracle critical Patch for Siebel CRM in Jan 2024

edited Jan 18, 2024 2:47PM in Siebel System Admin, Install and Upgrade (MOSC) 2 commentsAnswered

Hi, Oracle releases recently the critical patch for Jan 2024 and 2 of the CVE's are in the list

CVE-2023-1436 and CVE-2023-44487.

When I check the Risk Matrix it says Vulnerability in Siebel CRM Product referring component EAI and UI pointing to Jettison and Apache Tomcat. Possibility of successful attacks can result in unauthorized access.

The only resolution mentioned is to update Patch 23.12. Is there any details document what exactly the issue and how 23.12 version fixed the issue. In 23.12 release notes I couldn't find the fix of these 2 CVE's. Is there new Tomcat version in 23.12 that solves?


Would like to see the details on what was the issue and how 23.12 patch is the resolution (despite no information on these 2 CVE's in 23.12 fix release notes)?

Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center