Impact
A flaw in Oracle Siebel Apps – Marketing permits a low‑privileged attacker with network connectivity via HTTP to exploit the system. Successful exploitation allows the attacker to gain full control of the marketing component, compromising confidentiality, integrity, and availability of the application.
Affected Systems
Oracle Siebel Apps – Marketing versions 17.0 through 26.6 are vulnerable. The issue resides in the Marketing component of the Siebel CRM product.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 demonstrates high severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation. The vulnerability is not catalogued in CISA’s KEV list. The attack vector is a low‑privileged attacker with network access via HTTP and does not require user interaction.
OpenCVE Enrichment