Impact
Oracle Siebel CRM Integration's REST component contains a vulnerability that permits an unauthenticated attacker with network access via HTTPS to compromise the system. A successful exploitation allows the attacker to create, delete, or modify critical data, and to obtain full access to all data accessible through Siebel CRM Integration. The impact covers both confidentiality and integrity of the system’s data, as reflected in the CVSS 3.1 Base Score of 7.4.
Affected Systems
The affected product is Oracle Siebel CRM Integration, versions 17.0 through 26.6. Any installation of these versions running the REST service is susceptible to the described flaw.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, and the EPSS score of < 1% indicates a very low exploitation probability. The flaw is exploitable over the network via HTTPS without authentication, and the vulnerability is not listed in CISA’s KEV catalog. Businesses should consider the potential for significant data loss or corruption if the flaw is leveraged.
OpenCVE Enrichment