Description
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Siebel Server Sync for Exchange component of Oracle Siebel CRM Integration. An unauthenticated attacker who can reach the service over HTTP can issue requests that update, insert, or delete data that is normally protected. Successful exploitation therefore results in unauthorized modifications to CRM data, compromising the system’s integrity.

Affected Systems

Oracle Siebel CRM Integration, versions 17.0 through 26.5, which include the Siebel Server Sync for Exchange component.

Risk and Exploitability

The base CVSS score of 3.7 indicates a low to moderate potential impact on data integrity. The EPSS score of less than 1% suggests this vulnerability is rarely exploited in the wild, and it is not listed in the CISA KEV catalog. The attack vector is an unauthenticated HTTP request to the Siebel Server Sync endpoint, requiring only network connectivity to the service.

Generated by OpenCVE AI on August 4, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Siebel CRM Integration, as released in the 2026 July CPU.
  • Restrict access to the Siebel Server Sync for Exchange endpoint with firewall rules or access control lists so that only trusted networks or VPNs can reach it.
  • Enable detailed logging and monitoring of data modification events and regularly review the logs to detect any unauthorized changes.

Generated by OpenCVE AI on August 4, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle Siebel CRM Integration

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle Siebel CRM Integration

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification Vulnerability in Oracle Siebel CRM Integration
Weaknesses CWE-284

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification Vulnerability in Oracle Siebel CRM Integration
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle siebel Crm Integration
CPEs cpe:2.3:a:oracle:siebel_crm_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Integration
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Siebel Crm Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:33:41.548Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60357

cve-icon Vulnrichment

Updated: 2026-07-24T18:32:21.966Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses