Impact
The vulnerability resides in the Migration component of Oracle Siebel CRM Deployment. A low‑privileged network attacker who can reach the system over HTTP can exploit the flaw to gain unauthorized access to critical data and, due to a scope‑changing flaw, can also perform unauthorized update, insert, or delete operations on data that the attacker can normally read. The impact on confidentiality is high and the integrity of data is at least moderate.
Affected Systems
The affected product is Oracle Siebel CRM Deployment, versions 17.0 through 26.6 inclusive. The issue is relevant to any environment that runs these releases and exposes the Migration component to HTTP traffic.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.5 indicates severe impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the CVSS vector, the assault requires network access over HTTP and low privilege, but the S:C scope change means a successful exploit can grant higher privileges or wider access than the original attacker’s. The vulnerability is therefore highly exploitable in environments where the Migration component is not properly isolated or firewall‑restricted.
OpenCVE Enrichment