Impact
A vulnerability exists in the Open Integration component of Oracle Siebel CRM Integration that allows a high‑privileged attacker with network access via HTTP to create, delete, or modify critical data and to repeatedly crash the service. The flaw provides integrity and availability impacts, as indicated by a CVSS 3.1 base score of 7.7 and an availability impact of complete denial of service.
Affected Systems
Oracle Siebel CRM Integration, versions 25.12 to 26.6 inclusive, are affected. The vulnerability is present only in the Open Integration component and is reachable through standard HTTP interfaces.
Risk and Exploitability
The CVSS score of 7.7 reflects a high severity attack that requires high privileges and network access, but the description notes that exploiting the flaw is difficult. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can change scope and affect additional products, the potential impact extends beyond the immediate component if the attacker gains sufficient privilege or access. The attack vector is inferred to be remote network access over HTTP, exploiting a privilege‑management flaw that permits unauthorized operation of the integration service.
OpenCVE Enrichment