Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows physical access to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).
Published: 2026-07-21
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Event Publish and Subscribe component of Oracle Siebel CRM Integration and requires physical access to be exploited. It allows an attacker with such access to read a subset of data that the integration component exposes, leading to a modest confidentiality breach. The weakness is rated low in CVSS terms, with a Base Score of 1.9 and a vector indicating high attack complexity and high privileges, but no user interaction or remote component.

Affected Systems

Oracle Corporation’s Siebel CRM Integration is impacted for versions 17.0 through 26.4. No other products are listed as affected, but attacks may have broader effects on other integrated products due to scope change.

Risk and Exploitability

Given the need for physical presence and high privileges, the EPSS score is under 1% and the vulnerability is not listed in CISA KEV, indicating a low likelihood of exploitation. Nonetheless, the confidentiality impact warrants vigilance: implement physical security controls, enforce least‑privilege on integration accounts, and apply any forthcoming Oracle patch or firmware update as soon as it becomes available.

Generated by OpenCVE AI on August 4, 2026 at 05:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict and monitor physical access to servers that host Siebel CRM Integration, ensuring only authorized staff can enter the facilities.
  • Enforce least‑privilege for application accounts used by the Event Publish and Subscribe component, limiting read permissions to only the data necessary for normal operation.
  • Apply any available Oracle patch or update for Siebel CRM Integration as soon as it is released; monitor Oracle CPU advisories for new fixes.
  • Conduct regular audits of integration logs to detect unauthorized data reads and verify that no privilege escalation has occurred.
  • Follow Oracle's guidance for CWE-200 to ensure the component does not unnecessarily expose sensitive data.

Generated by OpenCVE AI on August 4, 2026 at 05:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Physical-Access Vulnerability Exposing Sensitive Data in Siebel CRM Integration

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Limited Confidentiality Impact from Physical Access to Oracle Siebel CRM Integration Event Publish and Subscribe
Weaknesses CWE-285

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Limited Confidentiality Impact from Physical Access to Oracle Siebel CRM Integration Event Publish and Subscribe
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows physical access to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 1.9, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Oracle Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:17:22.755Z

Reserved: 2026-05-18T15:55:10.317Z

Link: CVE-2026-47016

cve-icon Vulnrichment

Updated: 2026-07-23T15:17:12.709Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor