Impact
The vulnerability resides in the Siebel Server Sync for Exchange component of Oracle Siebel CRM Integration. An unauthenticated attacker who can reach the service over HTTP can issue requests that update, insert, or delete data that is normally protected. Successful exploitation therefore results in unauthorized modifications to CRM data, compromising the system’s integrity.
Affected Systems
Oracle Siebel CRM Integration, versions 17.0 through 26.5, which include the Siebel Server Sync for Exchange component.
Risk and Exploitability
The base CVSS score of 3.7 indicates a low to moderate potential impact on data integrity. The EPSS score of less than 1% suggests this vulnerability is rarely exploited in the wild, and it is not listed in the CISA KEV catalog. The attack vector is an unauthenticated HTTP request to the Siebel Server Sync endpoint, requiring only network connectivity to the service.
OpenCVE Enrichment