Impact
A flaw in the Siebel CRM Integration REST component allows an unauthenticated attacker who can reach the HTTP endpoint to create, delete, or modify critical data. The vulnerability bypasses normal access controls, causing confidentiality and integrity compromise of all data exposed through the integration. The weakness is identified as insecure direct object reference (CWE‑1284).
Affected Systems
Oracle Siebel CRM Integration versions 17.0 through 26.6 are affected. Any installation of these releases that exposes the REST interface to the network is susceptible. Clients should verify whether their instance exposes the REST API externally; if so, the risk is present.
Risk and Exploitability
The CVSS v3.1 score of 7.4 reflects a high severity with significant confidentiality and integrity impact. Exploitation requires only network access to the HTTP endpoint and no authentication, but the description notes the attack path is difficult to exploit. The EPSS score is below 1%, indicating a low likelihood of current exploitation, and the vulnerability is not listed in CISA KEV. Attackers would craft and send unauthorized REST requests to a vulnerable instance to change or destroy data.
OpenCVE Enrichment