Impact
A flaw in the Installation component of Oracle Siebel CRM Deployment allows an attacker who has a low‑privileged account and can log into the host running the product to exploit the vulnerability. The exploitation can lead to full takeover of the deployment, exposing, modifying, or deleting sensitive customer data and disrupting service. The impact covers confidentiality, integrity, and availability as reflected in a CVSS base score of 7.8.
Affected Systems
Oracle Siebel CRM Deployment versions 17.0 through 26.6 inclusive are affected. The vulnerability applies to the installation component of the product.
Risk and Exploitability
The CVSS vector states a local attack (AV:L) with low privilege (PR:L) and no user interaction (UI:N). Exploitation requires only low‑privileged host access and is considered easily doable. EPSS is less than 1% and the flaw is not in the CISA KEV catalog, indicating no proven widespread exploitation yet, but the high impact and low effort necessitate prompt action.
OpenCVE Enrichment