Impact
The vulnerability exists in the Installation component of Oracle Siebel CRM Deployment. An attacker who has a low‑privileged account that can log into the infrastructure host where the product runs can exploit the flaw and compromise the installation of Siebel CRM Deployment. Once exploited, the attacker can take over the deployment, gaining full control over the application, potentially exposing, modifying, or deleting customer data and disrupting service. The impact includes Confidentiality, Integrity, and Availability loss, as reflected in a CVSS score of 7.8.
Affected Systems
Oracle Siebel CRM Deployment, versions from 17.0 to 26.6 inclusive. These versions are affected by the flaw. Oracle’s security alert lists the affected releases. The installation component is part of the product.
Risk and Exploitability
The CVSS vector indicates a local attack requiring only low‑privileged access (AV:L AC:L PR:L UI:N). The exploit is considered easily exploitable and can be performed by any user logged into the host. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. Still, the high Confidentiality, Integrity, and Availability impact and low attack effort warrant immediate remediation.
OpenCVE Enrichment