Impact
The flaw is a permission error (CWE‑284) that permits a low‑privileged attacker with network access over HTTP to create, delete, or modify any Siebel Apps – Marketing data. The vulnerability can also trigger a hang or repeated crash, affecting availability. Successful exploitation leads to integrity and availability violations for all data exposed by the application.
Affected Systems
Oracle’s Siebel Apps – Marketing product, versions 17.0 through 26.6, is affected. The product runs as a web application and exposes HTTP endpoints that any user with network access can reach. All builds within the stated version range contain the flaw regardless of configuration.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates severe risk to integrity and availability. The EPSS score is less than 1 %, suggesting a low probability of exploitation in the field, yet the vulnerability is present in all versions and has no CISA KEV listing. The defect is remotely exploitable via HTTP, removing the need for user interaction. Overall, it presents a high‑severity issue that should be mitigated promptly.
OpenCVE Enrichment