Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Application Interface component of Oracle Siebel CRM Deployment. An attacker who has low privileges and network access through HTTP can obtain unauthorized read access to a limited set of data that should be protected. The weak point arises from insufficient protection of information and a lack of proper access control, resulting in information disclosure (CWE‑203). The CVSS vector indicates a network attack, high attack complexity, low privileges, and user interaction from another person.

Affected Systems

Oracle Siebel CRM Deployment versions 17.0 through 26.4 are affected. These versions are part of Oracle Corporation’s Siebel CRM product line. No further version granularity is provided.

Risk and Exploitability

The base score of 2.6 and an EPSS lower than 1 % indicate a low overall risk and a very small likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to interact with a user who initiates the attack, making a successful breach unlikely but not impossible. Because of the confidentiality impact, it is advisable to apply the vendor patch as soon as it becomes available and consider containment measures until a fix can be deployed.

Generated by OpenCVE AI on August 4, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Oracle Siebel CRM Deployment patch or update when released
  • Restrict HTTP access to the Application Interface to trusted internal hosts and enforce strict access controls
  • Monitor logs for abnormal read requests to sensitive data and alert on potential exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via Low-Privilege HTTP API in Siebel CRM Deployment

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via Low-Privilege HTTP API in Siebel CRM Deployment

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Unauthorized Information Disclosure in Siebel CRM Deployment via HTTP
Weaknesses CWE-200
CWE-284

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Unauthorized Information Disclosure in Siebel CRM Deployment via HTTP
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:06:53.738Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47011

cve-icon Vulnrichment

Updated: 2026-07-23T15:06:03.407Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:06.623

Modified: 2026-08-05T17:04:07.077

Link: CVE-2026-47011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses