Impact
The vulnerability resides in the Search component of Oracle Siebel CRM End User and allows an unauthenticated attacker with access to the local physical network segment to create, delete, modify or gain unauthorized access to critical data. The flaw provides significant confidentiality and integrity impacts without affecting availability. The CVSS score of 8.1 denotes high severity.
Affected Systems
Oracle Siebel CRM End User versions 17.0 through 26.6 are affected. All installations of this product that rely on the Search module are at risk until a fix is applied.
Risk and Exploitability
The attack vector is local (physical network segment), requiring an attacker to be in proximity to the host system. While the EPSS score is reported as < 1%, the high CVSS score and the fact that no exploit is currently listed in CISA’s KEV catalog suggest that the risk is moderate to high for environments that expose the Siebel CRM End User over a local network segment. An attacker can exploit the flaw to tamper with or steal data, potentially leading to significant business impact.
OpenCVE Enrichment