Impact
This vulnerability resides in the Migration component of Oracle Siebel CRM Deployment. An unauthenticated attacker who can reach the system over HTTP can exploit a flaw that allows the attacker to compromise the deployment. Successful exploitation requires human interaction from a user who is not the attacker; if achieved, the attacker can take full control of the Siebel CRM Deployment, gaining confidentiality, integrity, and availability impacts. The CVSS 3.1 base score of 7.5 reflects significant impact across all three core security properties.
Affected Systems
Oracle Corporation’s Siebel CRM Deployment product, specifically the Migration component, is affected. Versions 17.0 through 26.6 are impacted. No other versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high level of severity, while the EPSS score is under 1%, indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the affected systems over HTTP, a network‑based entry, but the flaw requires legitimate user interaction from a third‑party user, diminishing the chance of automated attacks. This combination of remote access and required user involvement creates a moderate‑to‑high risk for organizations that expose Siebel CRM Deployment to untrusted networks.
OpenCVE Enrichment