Impact
A low‑privileged attacker with network access via HTTP can exploit a flaw in the Data Archival component of Oracle Siebel CRM Administration. The vulnerability allows unauthorized read access to sensitive information and, in some scenarios, insert, update, or delete operations on that data, compromising confidentiality and integrity. The weakness is rooted in improper access control (CWE‑284).
Affected Systems
Oracle Siebel CRM Administration versions 25.12 through 26.6, specifically the Data Archival component, are affected. The issue is present in all builds of the Administration interface within that version range.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 denotes a moderate‑to‑high risk impact. The EPSS score of less than 1% indicates a low probability of exploitation, but the flaw can be triggered over an accessible HTTP interface without elevated privileges. The vulnerability is not listed in CISA’s KEV catalog, suggesting no documented large‑scale exploitation yet, yet the ease of exploitation and high impact make it a priority to mitigate.
OpenCVE Enrichment