Impact
A flaw in the Marketing component of Oracle Siebel Apps – Marketing allows an attacker with low privileges to exploit a network‑based HTTP service. An attacker who can reach the marketing endpoint can use the vulnerability to fully compromise the application. The impact is total loss of confidentiality, integrity, and availability of the marketing application, resulting in disclosure of sensitive data, alteration or destruction of content, and denial of service for legitimate users. This weakness corresponds to CWE‑284 and CWE‑306.
Affected Systems
Oracle’s Siebel Apps – Marketing, versions 17.0 through 26.6, are vulnerable to this flaw. These versions include the Marketing component and are currently supported by Oracle.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 classifies this as a high‑severity issue with broad impact. The EPSS score of <1% (0.00417) indicates a very low probability of exploitation, but the existence of a network‑based, low‑privilege attack vector and the lack of a CISA KEV listing suggest a moderate risk of exploitation. An attacker would typically initiate a malicious HTTP request from an external or internal network host to the exposed Marketing service, leveraging the flaw to gain unauthorized control of the application.
OpenCVE Enrichment