Impact
The vulnerability resides in the Event Publish and Subscribe component of Oracle Siebel CRM Integration and requires physical access to be exploited. It allows an attacker with such access to read a subset of data that the integration component exposes, leading to a modest confidentiality breach. The weakness is rated low in CVSS terms, with a Base Score of 1.9 and a vector indicating high attack complexity and high privileges, but no user interaction or remote component.
Affected Systems
Oracle Corporation’s Siebel CRM Integration is impacted for versions 17.0 through 26.4. No other products are listed as affected, but attacks may have broader effects on other integrated products due to scope change.
Risk and Exploitability
Given the need for physical presence and high privileges, the EPSS score is under 1% and the vulnerability is not listed in CISA KEV, indicating a low likelihood of exploitation. Nonetheless, the confidentiality impact warrants vigilance: implement physical security controls, enforce least‑privilege on integration accounts, and apply any forthcoming Oracle patch or firmware update as soon as it becomes available.
OpenCVE Enrichment