GeeKs Blogging @ dotCOM

Let's share…
  • Home
  • About
  • Contribute
  • How To – FAQs
  • Disclaimer
  • Terms & Conditions
8 Mar 2010

Siebel : Security Vulnerability !

by Nitin Jain


This post could have far-reaching implications. I am still at crossroads whether I should be covering this or not..

The baseline is that there has been a Security Vulnerability detected, and announced. It is said to have been detected nearly a year ago, and informed to the Parent Organization. However, despite a year passing by, we are not aware of any remedial action having been taken by the Corporation. Since the vulnerability has already been publicly announced over the internet, we feel it’s safe to cover it here as well. We feel morally responsible to apprise Oracle Corp of the issue by building sufficient public opinion to patch it..

This Security Vulnerability has been detected in some of the older versions of Oracle’s very popular Siebel CRM Softwa=re, aka versions 7.7 and 7.8. It has not been tested on the older versions, but, expectedly it would appear there as well.

This Security Loophole has been detected by “Yaniv Miron”, a Security Researcher from Israel. Click here to reach his LinkedIn profile directly.

The vulnerability comes by the name of, “Oracle Siebel CRM ‘start.swe’ Cross Site Scripting Vulnerability”.

It is rated “Low Risk”, and is Remotely Exploitable.

The following is directly from VUPEN :
” ..This vulnerability could be exploited by attackers to execute arbitrary scripting code. This issue is caused by an input validation error in the “htim_enu/start.swe” script when processing user-supplied data, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user’s browser in the security context of an affected site.. “

SECUNIA says..
” ..Input passed via the URL to htim_enu/start.swe is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.. “

A simple example could be:

http://example.com/htim_enu/start.swe/?>'"><script>alert('XSS by Lament')</script>

Jan 2009 – Vulnerability found
Jan 2009 – Vendor Notification
Feb 2010 – Public Disclosure

Complete details about the vulnerability can be found at the following URLs where it was first reported:

http://www.vupen.com/english/advisories/2010/0516

http://seclists.org/bugtraq/2010/Mar/6

The original Advisories may be downloaded from the links below:
Siebel Loyalty Advisory
Siebel CRM Advisory

The vulnerability is already popular over Twitter.. try the link below..
Twitter Links for Siebel Advisory

Could there be better reasons to Upgrade to the latest Siebel versions, 8.x ?
Considering Siebel CRM is an expensive product targetted only at the companies with $250K+ revenues, this is all the more important.

Note: This post is for informational purposes only.
The author of this document is not and will not hold any responsibility for any illegal or unauthorized use of the information contained within this document, or that is implied from it.
The author of this document does not encourage in any way whatsoever, attacking any Siebel based System.



Related posts:

  1. Siebel – SIS OM PMT Service There are lots of vanilla business services available in Siebel...
  2. Siebel – Forcing User Logoff Hi all, Somebody recently asked me if there is a...
  3. Siebel – LookUpName() and LookUpValue() Hi all, I was working for a multi lingual implementation...
  4. Siebel – HTML Code displayed in Error Message There was a requirement in our project to make Account...
  5. Siebel – Upgrade Process – Part I If you have reached here, I assume you have already...
  6. Siebel – Automatic User Logout Logging out a user automatically, when the user does not...
  7. Siebel – Upgrade Roadmap – Part II This is a continuation of my previous post, Siebel –...

Tags: Security, Siebel



For regular updates, enter your email address below. We don't spam, we don't share with others!




This entry was posted on Monday, March 8th, 2010 at 1:17 AM and is filed under Siebel CRM. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

Click here to cancel reply.


« 10 Reasons to Adopt Salesforce.com
Siebel – Why Upgrade? – Part I »



  • Admin Controls

    • Log in
  • Talk to us

    • Bouquets, brickbats, suggestions, complaints?

    • Click here...
  • Authorships

    • We are currently looking out for active authors. Are you willing to contribute?

    • Please click here

    • Everyone's invited..
  • Subscribe by Email


    • For regular updates, enter your email address below. We don't spam, we don't share with others!

  • Sponsors

  • Subscribe

    • Entries (RSS)
    • Comments (RSS)
  • Siebel Bookshelf

  • Daily Dilbert

    •          
  • Categories

    • Admin Notifications (9)
    • Business Intelligence (2)
      • Actuate (2)
    • CRM (115)
      • CRM News (6)
      • Sage Software / ACT! (1)
      • Salesforce.com (2)
      • Siebel CRM (103)
    • EAI (2)
    • Events (1)
    • FUN 'n' FROLIC (6)
    • Hot Technologies (7)
    • IT News (47)
    • Meet the Author (9)
    • ORACLE (14)
      • Database (2)
      • Oracle Fusion Applications Stack (8)
    • Product Demostrations (5)
    • Uncategorized (4)
  • Tag Cloud

    Admin Admin Notifications Applet Author Introductions Business Component Calculated Function Certification CFG file Client Configuration Critique CRM Database Debugging EAI EIM eScript Fundamentals Fusion Middleware Google IT News License Login Microsoft ORACLE Oracle Fusion Applications Performance problems Product Defect Product Demostrations Salesforce Scriptless solutions Security Server Siebel Siebel Secrets SOA Tips Tools Tricks Tutorials Upgrade User Property Workarounds workflows



  • Archives

    • August 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • November 2010
    • August 2010
    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
  • Authors

    • Ankit Bhardwaj
    • Ashish Kaul
    • brijesh
    • Himanshu Bajpai
    • Madhvi Arora
    • nanpats
    • Nitin Jain
    • Prachi Sharma
    • Renuka Ankam
    • Vikas Luthra
  • Administrators

    • geeksblogging@gmail.com
    • admin@geeksbloggingat.com
  • Sponsors

Fresh Ideas

  • Login Failed in Dedicated Web Client : MVF Issue
  • Oracle Fusion Applications price list
  • Research to Development - Fusion Apps Series
  • Oracle ACE Program
  • HCM user Experience through UI - Fusion Apps series
  • "Managing Oracle Fusion Applications"
  • Microsoft *previews* Windows 8 - Part 2 now available !!
  • Let's upgrade Siebel CRM to Fusion Apps "right now" !!
  • Ness Technologies bought out by Citigroup Unit
  • Oracle #1 CRM Applications vendor ??

Just Said

  • Amit Sharma on Siebel – Installer hangs midway
  • Khadijah Mosinski on Salesforce.com not upto the mark?
  • Hamre319 on Highrise Customer Relationship Management
  • Nitin Jain on “Managing Oracle Fusion Applications”
  • zama racha on “Managing Oracle Fusion Applications”
  • Nishant Aggarwal on Siebel – License keys don’t work / are invalid
  • Nitin Jain on Siebel – SIA BC Utility Service – Invoke BC Method
  • Pedro Garcia on Siebel – SIA BC Utility Service – Invoke BC Method
  • Nitin Jain on “Managing Oracle Fusion Applications”
  • Nitin Jain on Microsoft *previews* Windows 8 – Part 2 now available !!

Most Commented

  • Siebel - SIA BC Utility Service - Loop multiple records
  • Siebel - Installer hangs midway
  • Siebel - Adding License Keys to Sample
  • Siebel - Popup Update Only
  • Siebel - Reading data directly from Siebel SRF
  • Siebel - Automatic User Logout
  • Siebel - EAI Queue - Usage
  • Siebel - Looping multiple records - Update records
  • Siebel - SIS OM PMT Service
  • Siebel Tools hangs when checking out objects

Old Favourites

  • Highrise Customer Relationship Management
  • Siebel - Autosave Opportunity data - Sample Code
  • Siebel - Autosave Opportunity data - The concept
  • Renuka Ankam
  • Siebel - Merge Records - Checklist
  • Siebel - Fetch Active view properties - III
  • Oracle 11g Certification coming soon
  • Siebel - Fetch Active view properties - II
  • Siebel - Fetch Active view properties
  • Siebel - Automating Merge Records by script - II

If you also want to write on GeeksBlogging@dotCOM, click here. Area of Specialization no constraint. Become Famous!


Entries (RSS) and Comments (RSS).