Impact
A flaw in the Open Integration component of Oracle Siebel CRM allows a low‑privilege attacker possessing network access via HTTP to exploit the system. The vulnerability directly compromises confidentiality, integrity, and availability, potentially leading to a complete compromise of the Siebel CRM Integration service and affecting other connected applications.
Affected Systems
Oracle Corporation’s Siebel CRM Integration product, versions 25.12 through 26.6, is affected. Only the Siebel CRM Integration component is formally listed as vulnerable; other Oracle Siebel products may experience a scope change if compromised.
Risk and Exploitability
The CVSS score of 9.9 classifies this as critical, with the attack vector being network‑based (HTTP) and requiring low privilege. The EPSS score is below 1%, indicating a very low exploitation probability, but the high severity and ease of exploitation warrant immediate attention. The vulnerability can be leveraged by an attacker to gain full control over the integration module from a remote location without authentication, and the KEV catalog indicates it is not listed.
OpenCVE Enrichment