Impact
The vulnerability resides in the Data Archival component of Oracle Siebel CRM Administration. It permits an unauthenticated attacker who can reach the system over HTTP to compromise the administration interface. The weakness allows the attacker to bypass authentication and obtain or modify sensitive data stored in Siebel CRM Administration, potentially affecting the confidentiality of business information. No integrity or availability impact is reported, but the adversary can gain full access to all data exposed through the affected component.
Affected Systems
Oracle’s Siebel CRM Administration product is impacted. Affected versions span from 25.12 through 26.6 of the product. This includes all installations of the Data Archival component within those version ranges.
Risk and Exploitability
The CVSS 3.1 score of 8.6 indicates a high severity with a network attack vector, low attack complexity, and no user interaction required. The lack of a known exploitation probability (EPSS not available) suggests a recognized but unquantified risk. The vulnerability is not listed in CISA’s KEV catalog, yet because the weakness allows unauthenticated access and scope change, it can still expose broader systems and data. The likely attack path is an HTTP request to the vulnerable endpoint, exploiting the missing authentication controls, which can be performed remotely without any special user credentials.
OpenCVE Enrichment