Impact
The vulnerability resides in the REST component of Oracle Siebel CRM Integration and permits an unauthenticated attacker to access any data exposed by the integration. The flaw can also trigger a partial denial of service. It is an improper access control weakness that violates confidentiality and availability goals.
Affected Systems
Oracle Siebel CRM Integration, versions 17.0 through 26.6 the product is affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 indicates a high severity. The EPSS score is < 1% and the issue is not listed in CISA’s KEV catalog. The likely attack vector is an external network attacker sending HTTP requests to the exposed REST interface. In the absence of authentication, the attacker can retrieve critical data and, by abusing the interface, may cause a partial denial of service.
OpenCVE Enrichment