Impact
An unauthenticated external attacker who can reach the Siebel CRM Integration REST API over HTTP can create, delete, or modify critical data without any authentication. The flaw allows the attacker to bypass normal access controls, resulting in confidentiality and integrity compromise of all data accessible through the integration. This weakness is consistent with an Improper Access Control flaw (CWE-284).
Affected Systems
Oracle Siebel CRM Integration 17.0 through 26.6 are affected. Any installation of these versions that exposes the REST interface to a network is susceptible to exploitation.
Risk and Exploitability
The CVSS v3.1 score of 7.4 indicates high severity with significant confidentiality and integrity impact, but without network exploitation prerequisites. Exploitation requires only network access to the HTTP endpoint, making it possible from any system able to reach the API, though the vulnerability is described as difficult to exploit. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV. Attackers would send crafted REST requests to a vulnerable instance to gain unauthorized access and modify or delete data.
OpenCVE Enrichment