Impact
The vulnerability resides in the Application Interface component of Oracle Siebel CRM Deployment. An attacker who has low privileges and network access through HTTP can obtain unauthorized read access to a limited set of data that should be protected. The weak point arises from insufficient protection of information and a lack of proper access control, resulting in information disclosure (CWE‑203). The CVSS vector indicates a network attack, high attack complexity, low privileges, and user interaction from another person.
Affected Systems
Oracle Siebel CRM Deployment versions 17.0 through 26.4 are affected. These versions are part of Oracle Corporation’s Siebel CRM product line. No further version granularity is provided.
Risk and Exploitability
The base score of 2.6 and an EPSS lower than 1 % indicate a low overall risk and a very small likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to interact with a user who initiates the attack, making a successful breach unlikely but not impossible. Because of the confidentiality impact, it is advisable to apply the vendor patch as soon as it becomes available and consider containment measures until a fix can be deployed.
OpenCVE Enrichment