Impact
Oracle Siebel Apps Self Service contains an unauthenticated HTTP vulnerability in its Helpdesk/Training component that permits an attacker with network access to submit crafted requests that can create, modify, or delete critical data. Successful exploitation would compromise the confidentiality and integrity of all data accessible through the Self Service interface.
Affected Systems
Oracle Siebel Apps – Self Service, specifically the Helpdesk/Training component, with affected releases ranging from version 17.0 up to 26.6. Only installations of the Self Service product are directly vulnerable, but the impact extends to all data exposed by the application.
Risk and Exploitability
The CVSS v3.1 base score of 9.3 classifies this weakness as critical, while the EPSS score of less than 1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need only to send unauthenticated HTTP requests; however, successful breach requires a separate human interaction from a user not controlled by the attacker. Given the high severity and minimal authentication barrier, the overall risk to organizations running the affected software remains elevated.
OpenCVE Enrichment