Impact
A vulnerability exists in the Open Integration component of Oracle Siebel CRM Integration that can be exploited by an attacker with low privileges and network access through HTTP. The exploit allows the attacker to read critical data and perform unauthorized updates, inserts or deletions, thereby breaching confidentiality and partially affecting integrity. The CVSS 3.1 vector indicates a high confidentiality impact and a low integrity impact, with a base score of 8.5.
Affected Systems
The affected asset is Oracle Siebel CRM Integration, specifically the Open Integration component within versions 25.12 through 26.6. The vulnerability may also indirectly affect other products that rely on Siebel CRM Integration, expanding its potential impact beyond the primary scope.
Risk and Exploitability
With an AV:N attack vector, AC:L and PR:L, the vulnerability is considered easily exploitable. Although the EPSS score is not available, the absence of KEV listing does not lessen the urgency. The low privileged attacker only needs network connectivity to the HTTP interface, a common entry point in many environments, which raises the risk of successful exploitation. The potential to read and modify sensitive data, coupled with the relatively high CVSS score, warrants immediate attention.
OpenCVE Enrichment