Impact
Vulnerability in the REST component of Oracle Siebel CRM Integration allows an unauthenticated attacker with network access over HTTPS to create, delete, or modify critical data. Because authentication is not required, the flaw can lead to unauthorized disclosure of information and significant integrity violations, potentially affecting all data exposed by the integration.
Affected Systems
Affected products are Oracle Siebel CRM Integration. Supported versions 17.0 through 26.6 are vulnerable. All environments running these versions are at risk unless updated.
Risk and Exploitability
The CVSS v3.1 score of 7.4 indicates a high impact on confidentiality and integrity but no impact on availability. Exploitation requires only network access over HTTPS and is described as difficult; the EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Despite the lack of availability impact, the absence of authentication makes this a serious threat for systems exposed to external connections.
OpenCVE Enrichment