Impact
The vulnerability in Oracle Siebel CRM Integration allows an unauthenticated attacker with network access to HTTP to compromise the system. The attack requires the victim to perform an action, indicating a social‑engineering component. Once exploited, the attacker can create, delete, or modify critical data and gain complete access to all data exposed through Siebel CRM Integration, resulting in high confidentiality and integrity losses.
Affected Systems
Oracle Siebel CRM Integration Versions 25.12 through 26.6 are affected. No other products or versions are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score is 8.1, reflecting a high impact on confidentiality and integrity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV. The exploitation path is a low‑complexity network attack that requires user interaction. Because the vulnerability permits data manipulation without authentication, the risk to affected environments is significant and a patch or upgrade is strongly recommended.
OpenCVE Enrichment