Description
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 2.6 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L).
Published: 2026-07-21
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Redwood UI component of Oracle Siebel CRM End User and is inherited by support versions 24.4 through 26.3. It allows an attacker with high privileges and network access over HTTP to initiate a partial denial of service on the application. The attack requires user interaction from a person who is not the attacker, meaning an external user must engage with the application for the vulnerability to be exercised. No confidentiality or integrity impact is reported.; the weakness is classified as CWE‑284: Improper Authorization.

Affected Systems

Oracle Corporation’s Siebel CRM End User product, specifically the Redwood UI component, is affected for supported versions 24.4 to 26.3. The product is the only one explicitly listed as impacted, but the description notes potential scope changes to other related applications.

Risk and Exploitability

The CVSS base score of 2.6 reflects a low severity availability issue. The EPSS score of less than 1 % suggests a very low probability of active exploitation as of the data provided. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits at this time. Exploitation requires a high-privileged user, network access over HTTP, and the cooperation of a third‑party user, which limits the ease of successful attacks. Because the scope can widen to additional products, a successful compromise could affect more systems than the original target.

Generated by OpenCVE AI on August 4, 2026 at 05:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses the Redwood UI flaw for all affected version ranges (24.4–26.3).
  • Restrict external HTTP traffic to the Siebel CRM End User servers by using firewall rules or VPN tunnels, limiting access to trusted network segments.
  • Enforce strict least‑privilege policies on all user accounts that interact with the Siebel CRM End User application.

Generated by OpenCVE AI on August 4, 2026 at 05:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Improper Authorization in Siebel CRM Redwood UI

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title High Privileged Attacker Can Induce Partial Denial of Service in Oracle Siebel CRM End User via HTTP
Weaknesses CWE-285

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title High Privileged Attacker Can Induce Partial Denial of Service in Oracle Siebel CRM End User via HTTP
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI). Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 2.6 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L).
First Time appeared Oracle
Oracle siebel Crm End User
CPEs cpe:2.3:a:oracle:siebel_crm_end_user:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm End User
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L'}


Subscriptions

Oracle Siebel Crm End User
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:07:16.517Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47032

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:27.818Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses