Impact
A flaw in the Data Archival component of Oracle Siebel CRM Administration allows an attacker with network access via HTTP to gain full control of the administration interface without authentication. The vulnerability is described as easily exploitable and can lead to a complete takeover, compromising confidentiality, integrity, and availability of the system.
Affected Systems
Oracle Siebel CRM Administration, versions 25.12 through 26.6, is affected by this vulnerability. The issue resides in the Data Archival component of these releases.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 categorizes this as a critical vulnerability. The EPSS score of less than 1% indicates a very low but non-zero exploitation probability, and it is not listed in the CISA KEV catalog. The likely attack vector is over network-based HTTP, requiring no authentication; an attacker can send crafted requests to exploit the flaw and achieve total administrative takeover.
OpenCVE Enrichment