Impact
A flaw in Oracle Siebel CRM Integration, specifically the Open Integration component, allows an attacker who can reach the service via HTTP to authenticate no credentials and execute arbitrary actions on the target system. The vulnerability can be leveraged to compromise the integrity and confidentiality of the CRM integration subsystem, potentially leading to full control of the service and access to sensitive customer data.
Affected Systems
Oracle Siebel CRM Integration versions 25.12 through 26.6 are known to be affected. The issue resides in the Open Integration component of the product.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 indicates critical severity, with high impact on confidentiality, integrity, and availability. No EPSS score is currently available and the issue is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated HTTP network access, with low attack complexity and no user interaction required, meaning the risk of exploitation is high for exposed services.
OpenCVE Enrichment