Impact
The vulnerability resides in the Application Interface of the Siebel CRM Deployment product. An unauthenticated attacker who can reach the physical communication segment that hosts the application can exploit the flaw to create, delete or modify data. Successful exploitation results in unauthorized access to or complete compromise of all data stored or processed by Siebel CRM Deployment, threatening both confidentiality and integrity.
Affected Systems
Oracle Siebel CRM Deployment is affected for all supported versions from 17.0 through 26.6. The flaw is present in the Application Interface component of the system.
Risk and Exploitability
The flaw is rated with a CVSS 3.1 base score of 8.1, indicating high severity. The exploit vector is local (AV:A) with low attack complexity (AC:L). The EPSS score is 0.00225 (<1%), indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Given that the attack requires physical or network segment access to the deployment, the flaw can be considered easily exploitable under those conditions, but the overall likelihood reflected by EPSS remains low.
OpenCVE Enrichment