Impact
The vulnerability resides in Oracle Siebel CRM Integration’s Open Integration component and permits a low-privileged attacker with network access via HTTP to compromise the component entirely. By exploiting this flaw, an attacker can read, modify, or delete data and disrupt services, thereby affecting confidentiality, integrity, and availability. The description indicates that a scope change can extend the impact to additional products.
Affected Systems
Affected versions are 25.12 through 26.6 of Oracle Siebel CRM Integration, distributed by Oracle Corporation. No other vendors are directly mentioned in the CNA data.
Risk and Exploitability
The CVSS 3.1 base score of 8.5 signals high severity, while the attack vector is network, with high complexity and low privilege. The EPSS score is less than 1%, which indicates a very low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the CVE notes a scope change, a successful compromise of Siebel CRM Integration could potentially impact additional integrated products, raising overall risk.
OpenCVE Enrichment