Impact
The vulnerability in the Open Integration component of Oracle Siebel CRM Integration allows an unauthenticated attacker with access to the physical network segment where the integration runs to create, delete, or modify data. Such an attacker can gain unauthenticated access to critical data or complete control over all data accessible by the integration, compromising confidentiality and integrity. The CVSS vector indicates a local network attack (AV = A) with low authentication and no interaction, resulting in a high severity score of 8.1.
Affected Systems
Oracle Corporation’s Siebel CRM Integration, especially the Open Integration component, is affected in versions from 25.12 through 26.6. All releases within this version range carry the vulnerability, impacting the integration service on the specified hardware.
Risk and Exploitability
Exploitation requires physical or local network access to the hardware on which Siebel CRM Integration is executed. While the EPSS score is currently unavailable, the high CVSS severity and lack of exposure in the CISA KEV catalog suggest a moderate to high exploitation likelihood in environments where local access is possible. The attack vector is local, making physical security and network segmentation critical to mitigating this risk.
OpenCVE Enrichment