LiveActive security incident?Get immediate response
CVE Record

CVE-2021-2338: Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing Stand...

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing Stand-Alone). Supported versions that are affected are 21.5 and Prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel Apps - Marketing accessible data as well as unauthorized read access to a subset of Siebel Apps - Marketing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

MediumCVSS 6.1Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a data exposure and tampering risk in Oracle Siebel CRM marketing email functions. An outside attacker could reach it over HTTP, but the attack requires another person's interaction. The reported impact is limited read access and limited data changes, not system outage.

Executive priority

Treat this as a medium-priority CRM data integrity issue. Prioritize remediation if Siebel Marketing is externally reachable, supports customer campaigns, or contains regulated customer data.

Technical view

CVE-2021-2338 affects Oracle Siebel Apps - Marketing Email Marketing Stand-Alone versions 21.5 and prior. It is network reachable over HTTP, unauthenticated, low complexity, requires user interaction, and has changed scope. Successful attack can allow unauthorized read and update, insert, or delete access to some accessible data, with no availability impact reported.

Likely exposure

Organizations running Oracle Siebel CRM Marketing, specifically Email Marketing Stand-Alone version 21.5 or earlier, are the likely exposed group. Internet or broad network HTTP reachability increases practical risk.

Exploitation context

The provided sources do not show KEV listing or active exploitation. The CVSS vector indicates exploitation is unauthenticated over HTTP but requires user interaction, so phishing or user-driven workflow abuse is a plausible context.

Researcher notes

No CWE is provided in the source bundle. Scope changed means impact may cross component boundaries. Validation should focus on version, component enablement, HTTP reachability, and whether Oracle CPU remediation is present.

Mitigation direction

  • Identify Siebel Apps - Marketing deployments and confirm Email Marketing Stand-Alone usage.
  • Check Oracle July 2021 CPU guidance for the applicable Siebel remediation.
  • Apply Oracle-supported fixes or upgrades for affected versions where available.
  • Limit HTTP exposure to trusted networks while remediation is planned.
  • Monitor vendor advisories for later Siebel guidance or superseding patches.

Validation and detection

  • Inventory Siebel Apps - Marketing versions and flag 21.5 or earlier.
  • Confirm whether Email Marketing Stand-Alone is enabled or reachable over HTTP.
  • Verify applicable Oracle CPU patches or supported upgrades are installed.
  • Review access logs for unusual HTTP activity against marketing email components.
  • Document any compensating network controls around affected Siebel services.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-2338 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.1CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N2.82.7Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

6.1Medium
CVSS 3.1 vector shape for CVE-2021-2338Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Oracle CorporationSiebel Apps - Marketing21.5 and PriorListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.