Impact
A recently announced weakness in Oracle Siebel CRM Integration’s REST component permits an unauthenticated user with network access over HTTP to read critical data. The flaw is easy to exploit and can lead to complete access to all data that the integration can reach. The CVSS 3.1 base score of 7.5 reflects a high confidentiality impact, while integrity and availability are unaffected.
Affected Systems
The vulnerability affects Oracle’s Siebel CRM Integration from versions 17.0 through 26.6. Only this product and the specified version range are known to be vulnerable.
Risk and Exploitability
The attack vector is network‑based over HTTP, requiring no authentication or elevated privileges. Because the flaw is easily exploitable and exposes sensitive data, the risk is significant for environments that expose the REST API to external networks. The EPSS score indicates a very low exploitation probability of less than 1% and the issue has not been listed in the CISA KEV catalog, but the high CVSS base score and lack of authentication requirements suggest that attackers could target this weakness with little effort.
OpenCVE Enrichment