Impact
The vulnerability exists in the Open Integration component of Oracle Siebel CRM Integration and allows an attacker who can reach the service over HTTP to create, delete, or modify critical data without authenticating. The vulnerability is difficult to exploit, but no authentication is required and the attack can lead to significant loss of confidentiality and integrity of all data exposed by the integration module. The description notes that the impact may extend to other related products, indicating a potential scope change during exploitation.
Affected Systems
Oracle Siebel CRM Integration version 25.12 through 26.6 are affected. Any deployment of the Open Integration component within that version range should be reviewed for exposure to the indicated HTTP access.
Risk and Exploitability
The CVSS v3.1 base score of 8.7 indicates high severity, driven by confidentiality and integrity impacts. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over network access via HTTP, with difficult to exploit and no authentication required. An attacker who successfully exploits the flaw can alter or delete data and gain unauthorized access, representing a high risk to information security for organizations running the affected versions.
OpenCVE Enrichment