GeeKs Blogging @ dotCOM

Let's share…
  • Home
  • About
  • How To – FAQs
  • Disclaimer
  • Terms & Conditions
8 Mar 2010

Siebel : Security Vulnerability !

by Nitin Jain



This post could have far-reaching implications. I am still at crossroads whether I should be covering this or not..

The baseline is that there has been a Security Vulnerability detected, and announced. It is said to have been detected nearly a year ago, and informed to the Parent Organization. However, despite a year passing by, we are not aware of any remedial action having been taken by the Corporation. Since the vulnerability has already been publicly announced over the internet, we feel it’s safe to cover it here as well. We feel morally responsible to apprise Oracle Corp of the issue by building sufficient public opinion to patch it..

This Security Vulnerability has been detected in some of the older versions of Oracle’s very popular Siebel CRM Softwa=re, aka versions 7.7 and 7.8. It has not been tested on the older versions, but, expectedly it would appear there as well.

This Security Loophole has been detected by “Yaniv Miron”, a Security Researcher from Israel. Click here to reach his LinkedIn profile directly.

The vulnerability comes by the name of, “Oracle Siebel CRM ’start.swe’ Cross Site Scripting Vulnerability”.

It is rated “Low Risk”, and is Remotely Exploitable.

The following is directly from VUPEN :
” ..This vulnerability could be exploited by attackers to execute arbitrary scripting code. This issue is caused by an input validation error in the “htim_enu/start.swe” script when processing user-supplied data, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user’s browser in the security context of an affected site.. “

SECUNIA says..
” ..Input passed via the URL to htim_enu/start.swe is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.. “

A simple example could be:

http://example.com/htim_enu/start.swe/?>'"><script>alert('XSS by Lament')</script>

Jan 2009 – Vulnerability found
Jan 2009 – Vendor Notification
Feb 2010 – Public Disclosure

Complete details about the vulnerability can be found at the following URLs where it was first reported:
http://www.vupen.com/english/advisories/2010/0516
http://seclists.org/bugtraq/2010/Mar/6

The original Advisories may be downloaded from the links below:
Siebel Loyalty Advisory
Siebel CRM Advisory

The vulnerability is already popular over Twitter.. try the link below..
Twitter Links for Siebel Advisory

Could there be better reasons to Upgrade to the latest Siebel versions, 8.x ?
Considering Siebel CRM is an expensive product targetted only at the companies with $250K+ revenues, this is all the more important.

Note: This post is for informational purposes only.
The author of this document is not and will not hold any responsibility for any illegal or unauthorized use of the information contained within this document, or that is implied from it.
The author of this document does not encourage in any way whatsoever, attacking any Siebel based System.

  • Twitter
  • Digg
  • Facebook
  • LinkedIn
  • Delicious
  • FriendFeed
  • Gmail
  • Hotmail
  • Multiply
  • MySpace
  • Yahoo Buzz
  • Yahoo Mail
  • Share/Bookmark

Related posts:

  1. Siebel – SIS OM PMT Service There are lots of vanilla business services available in Siebel...
  2. Siebel – Forcing User Logoff Hi all, Somebody recently asked me if there is a...
  3. Siebel – LookUpName() and LookUpValue() Hi all, I was working for a multi lingual implementation...
  4. Siebel – License keys don’t work / are invalid So, here I am again. After the fabulous solution to...
  5. Siebel – Upgrade Roadmap – Part II This is a continuation of my previous post, Siebel –...
  6. Siebel – Upgrade Process – Part I If you have reached here, I assume you have already...

Tags: Security, Siebel



This entry was posted on Monday, March 8th, 2010 at 1:17 AM and is filed under Siebel CRM. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

Click here to cancel reply.


« 10 Reasons to Adopt Salesforce.com
Siebel – Why Upgrade? – Part I »



  • Admin Controls

    • Log in
  • Talk to us

    • Bouquets, brickbats, suggestions, complaints?

    • Click here...
  • Authorships

    • We are currently looking out for active authors. Are you willing to contribute?

    • Please click here

    • Everyone's invited..
  • Subscribe by Email


  • Subscribe

    • Entries (RSS)
    • Comments (RSS)
  • Siebel Bookshelf

  • Daily Dilbert

    •          
  • Categories

    • Admin Notifications (9)
    • Business Intelligence (2)
      • Actuate (2)
    • CRM (106)
      • CRM News (3)
      • Sage Software / ACT! (1)
      • Salesforce.com (2)
      • Siebel CRM (98)
    • EAI (2)
    • FUN 'n' FROLIC (4)
    • Hot Technologies (2)
    • IT News (37)
    • Meet the Author (9)
    • ORACLE (5)
      • Database (2)
    • Product Demostrations (5)
    • Uncategorized (3)
  • Tag Cloud

    Admin Admin Notifications Applet Author Introductions Business Analysis Business Component Calculated Function Certification CFG file Client Configuration Critique CRM Database Debugging EAI EIM eScript Fundamentals Fusion Middleware Google IT News License Login Microsoft ORACLE Performance problems Product Defect Product Demostrations Salesforce Scriptless solutions Security Server Siebel Siebel Secrets SOA Tips Tools Tricks Tutorials Upgrade User Property Workarounds workflows



  • Archives

    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
  • Authors

    • Ankit Bhardwaj
    • Ashish Kaul
    • brijesh
    • Himanshu Bajpai
    • Madhvi Arora
    • nanpats
    • Nitin Jain
    • Prachi Sharma
    • Renuka Ankam
    • Vikas Luthra
  • Administrators

    • geeksblogging@gmail.com
    • admin@geeksbloggingat.com
  • Sponsors

Fresh Ideas

  • Siebel Openings - Contract to Hire
  • Google PAC-MAN
  • New Google Chrome Ads
  • Siebel Admin Mode Flag - II - Issue Log
  • Siebel - Admin Mode Flag
  • Narayan Patro
  • EAI Siebel Adapter BS - Upsert Multiple Child Records
  • Siebel - Upgrade Process - Part II
  • Siebel - Upgrade Process - Part I
  • Siebel - Upgrade Roadmap - Part II

Just Said

  • Nitin Jain on Siebel – Installer hangs midway
  • Narayan Patro on Siebel – Automatic User Logout
  • Nishant Gupta on Siebel – Installer hangs midway
  • Nitin Jain on Siebel Sales Wireless on Google Android
  • Sagar on Siebel Sales Wireless on Google Android
  • Nitin Jain on Siebel – Installer hangs midway
  • Thankful on Siebel – Installer hangs midway
  • Thota on Siebel EIM – Custom table mapping
  • Nitin Jain on Siebel – Upgrade Process – Part II
  • a siebel guy on Siebel – Upgrade Process – Part II

Most Commented

  • Siebel - SIA BC Utility Service - Loop multiple records
  • Siebel - Installer hangs midway
  • Siebel - Adding License Keys to Sample
  • Siebel - Popup Update Only
  • Siebel - Reading data directly from Siebel SRF
  • Siebel - EAI Queue - Usage
  • Siebel - Looping multiple records - Update records
  • Siebel - Automatic User Logout
  • Siebel - SIS OM PMT Service
  • Siebel Tools hangs when checking out objects

Old Favourites

  • Highrise Customer Relationship Management
  • Siebel - Autosave Opportunity data - Sample Code
  • Siebel - Autosave Opportunity data - The concept
  • Renuka Ankam
  • Siebel - Merge Records - Checklist
  • Siebel - Fetch Active view properties - III
  • Oracle 11g Certification coming soon
  • Siebel - Fetch Active view properties - II
  • Siebel - Fetch Active view properties
  • Siebel - Automating Merge Records by script - II

If you also want to write on GeeksBlogging@dotCOM, click here. Area of Specialization no constraint. Become Famous!


Entries (RSS) and Comments (RSS).