Impact
The vulnerability is found in the Marketing component of Oracle Siebel Apps - Marketing. A low‑privileged attacker who can reach the instance over HTTP can exploit the flaw to compromise the application. Successful exploitation can lead to a full takeover.
Affected Systems
Oracle Siebel Apps - Marketing, versions 17.0 through 26.6 are affected. The affected product is part of the Oracle Siebel CRM suite, specifically the Marketing application component.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high‑severity vulnerability with substantial impact on confidentiality, integrity, and availability. The EPSS score indicates a very low but non‑zero exploitation probability of less than 1%. The issue is not listed in CISA’s KEV catalog. The likely attack vector is over HTTP from a low‑privileged attacker. If successfully exploited, the attacker would gain full control over the application.
OpenCVE Enrichment