HTTP: Oracle Siebel Option Pack NewBusObj

This signature detects attempts to use unsafe ActiveX controls in Oracle Siebel Option Pack. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Oracle Siebel Option Pack for IE ActiveX control is prone to a remote code-execution vulnerability caused by a memory-initialization error. An attacker can exploit this issue to execute arbitrary code in the context of the application (typically Internet Explorer) using the ActiveX control. Failed attacks will likely cause denial-of-service conditions.

Affected Products

Oracle siebel_option_pack_for_ie_activex_control

Short Name
HTTP:STC:ACTIVEX:ORACLE-SIEBEL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2009-3737 NewBusObj Option Oracle Pack Siebel bid:42248
Release Date
01/13/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Oracle

CVSS Score

9.3

Found a potential security threat?