Impact
The flaw exists in the Redwood UI component of Oracle Siebel CRM End User and is inherited by support versions 24.4 through 26.3. It allows an attacker with high privileges and network access over HTTP to initiate a partial denial of service on the application. The attack requires user interaction from a person who is not the attacker, meaning an external user must engage with the application for the vulnerability to be exercised. No confidentiality or integrity impact is reported.; the weakness is classified as CWE‑284: Improper Authorization.
Affected Systems
Oracle Corporation’s Siebel CRM End User product, specifically the Redwood UI component, is affected for supported versions 24.4 to 26.3. The product is the only one explicitly listed as impacted, but the description notes potential scope changes to other related applications.
Risk and Exploitability
The CVSS base score of 2.6 reflects a low severity availability issue. The EPSS score of less than 1 % suggests a very low probability of active exploitation as of the data provided. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits at this time. Exploitation requires a high-privileged user, network access over HTTP, and the cooperation of a third‑party user, which limits the ease of successful attacks. Because the scope can widen to additional products, a successful compromise could affect more systems than the original target.
OpenCVE Enrichment