Impact
The vulnerability is an access control flaw in the Marketing component of Oracle Siebel CRM that can be triggered over HTTP by an attacker with low privileges. Exploitation grants unauthorized read or write access to critical data and can also cause a partial denial of service, disrupting the normal operation of the Marketing application.
Affected Systems
Affected are Oracle Siebel CRM customers running Siebel Apps – Marketing versions 17.0 through 26.6. Applications deployed in these versions can be reached over the network via standard HTTP endpoints, and are thus vulnerable to the flaw.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 reflects moderate to high impact on confidentiality and availability with a user interaction requirement of none and location of the vulnerability accessible over the network. Because the vulnerability is exploitable by remote low‑privileged users, the likelihood of detection and exploitation is high for exposed servers. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, but the ability to compromise sensitive data and affect application availability warrants prompt action.
OpenCVE Enrichment