Impact
The vulnerability resides in the Open UI component of the Oracle Siebel CRM End User product and allows a low‑privileged attacker with network access over HTTPS to compromise the application. Successful exploitation requires the attacker to have human interaction from a user other than the attacker, but it can result in unauthorized creation, deletion or modification of critical data and full unauthorized access to all data accessible through Siebel CRM End User. The impact affects confidentiality and integrity, and, due to application scope changes, could also influence other products that interact with the compromised system.
Affected Systems
Prerequisite for exploitation are the Oracle Siebel CRM End User versions 17.0 through 26.6, as those are the specifically supported versions identified as affected. No additional version data is provided.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 signals a high‑impact vulnerability, with the scaled vector reflecting network access, high attack complexity, low privilege, required user interaction, and a change of scope that allows the attacker to affect data beyond the initial target. The EPSS score is 0.00231 and indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating that no publicly confirmed exploitation has been documented to date. The likely attack vector is a remote HTTPS connection, where an attacker with limited permissions can send crafted requests once a user interacts with the vulnerable interface.
OpenCVE Enrichment