Impact
An unauthenticated attacker with network access to the Siebel Apps – Marketing HTTP interface can create, delete, or modify critical data or gain full access to all available data. This results in a loss of confidentiality and integrity of the application’s data, as the attacker can alter or wipe records. The vulnerability does not affect availability, but its exploitation grants extensive control over stored information.
Affected Systems
Oracle Siebel CRM’s Marketing component, versions 17.0 through 26.6, are vulnerable. All instances running these versions are exposed to the described attack vector via HTTP traffic.
Risk and Exploitability
The CVSS 3.1 score of 7.4 indicates a high severity risk, with high impact on confidentiality and integrity but no impact on availability. Although the EPSS score is not available, the public advisory and high CVSS suggest a moderate to high likelihood of exploitation. The vulnerability is reachable over the network without authentication or user interaction, and the attacker must have network visibility to the HTTP interface. As it is not listed in CISA’s KEV catalog, there is no current evidence of widespread exploitation, but the potential damage warrants prompt action.
OpenCVE Enrichment