RULE(RULE ID:335860)

Rule General Information
Release Date: 2021-12-20
Rule Name: Oracle Siebel Option Pack For IE ActiveX Control Code Execution Vulnerability (CVE-2009-3737)
Severity:
CVE ID:
Rule Protection Details
Description: The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://www.kb.cert.org/vuls/id/174089
http://www.vupen.com/english/advisories/2010/2028
Solutions
Upgrade to the latest version.