Impact
The vulnerability is an access control flaw in the Marketing component of Oracle Siebel CRM that can be triggered over HTTP by an attacker with low privileges. Exploitation grants unauthorized read or write access to critical data and can also cause a partial denial of service, disrupting normal operation of the Marketing application. The flaw is categorized as CWE‑284 and results in confidentiality impacts with partial availability degradation.
Affected Systems
Affected are Oracle Siebel CRM customers running Siebel Apps – Marketing versions 17.0 through 26.6. Applications deployed in these versions can be reached over the network via standard HTTP endpoints, and are thus vulnerable to the flaw.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 reflects moderate to high impact on confidentiality and availability with a user interaction requirement of none and a network‑reachable location. The EPSS score of less than 1% indicates very low overall exploitation probability, but the remote low‑privileged attacker model and lack of mitigation on exposed servers make exploitation possible. The vulnerability is not listed in CISA KEV, yet the potential to compromise sensitive data and affect application availability warrants prompt remediation.
OpenCVE Enrichment