Impact
An unauthenticated attacker with network connectivity to the Siebel Apps - Marketing HTTP interface can compromise the application due to a CWE‑284 weakness. The flaw grants unauthorized access to all data stored by the marketing component and enables an attacker to cause a hang or recurring crash, resulting in a denial of service. The CVSS v3.1 score of 9.1 reflects severe confidentiality impact and total availability impact.
Affected Systems
Oracle Siebel CRM’s Siebel Apps - Marketing product is affected. Versions from 17.0 up to and including 26.6 are vulnerable. Any installation within this range that exposes the HTTP interface to an external network can be exploited.
Risk and Exploitability
The high CVSS score indicates a critical severity. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is listed as not in CISA KEV, indicating no publicly confirmed exploitation yet. The attack vector is purely network based and requires no authentication; an unauthenticated HTTP connection to the vulnerable endpoint is sufficient to gain full data access and trigger service crashes.
OpenCVE Enrichment