Impact
The flaw is an improper access control issue in Oracle Siebel CRM Integration’s Open Integration component. An attacker who is not privileged but can reach the service over HTTP can bypass normal authentication checks and read any data exposed through the integration, potentially compromising sensitive business information. The vulnerability mainly affects confidentiality, but because the Flaw’s scope can expand to other products, a successful compromise could provide a foothold for further attacks.
Affected Systems
Oracle Siebel CRM Integration (Open Integration) versions 25.12 through 26.6 are affected. Systems that expose these services to external networks or accessible over public or untrusted internal networks are vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 7.7 reflects a high impact with confidentiality as the primary concern. The attack vector is clearly network‑based, the attack complexity is low, and the required privileges are low, with no user interaction. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ease of exploitation and potential for broader product impact warrant immediate remediation.
OpenCVE Enrichment