Impact
A vulnerability in Oracle Siebel Apps Marketing allows an unauthenticated attacker with network access via HTTP to take over the application. Because the flaw provides control over the system without requiring prior authentication, an attacker can read, modify, or delete data and potentially execute arbitrary code. The severity is reflected in a CVSS base score of 9.8, indicating high impacts on confidentiality, integrity, and availability.
Affected Systems
Oracle Siebel Apps Marketing versions from 17.0 through 26.5 are affected. The product is an integral component of Oracle Siebel CRM’s marketing functionality, and any deployment of these versions is at risk.
Risk and Exploitability
The vulnerability is assigned a low EPSS score of less than 1 %, suggesting that, while highly destructive, current exploitation activity is limited. It is not listed in the CISA KEV catalog. The attack vector is via the public HTTP interface and requires no prior authentication. Once accessed, the flaw can be leveraged to achieve full system takeover, with no constraints on the environment or prerequisite compromises.
OpenCVE Enrichment