Impact
A vulnerability in Oracle Siebel CRM Deployment allows a low‑privileged attacker with network access via HTTP to compromise the deployment. The flaw can be exploited without user interaction and enables the attacker to fully takeover the system, directly impacting confidentiality, integrity, and availability of the CRM environment. The effect is a full remote code execution scenario where an attacker can execute arbitrary commands on the deployed instance.
Affected Systems
Oracle Siebel CRM Deployment is affected for versions 17.0 through 26.6. The vulnerability is present in the Server Infrastructure component and can be triggered by HTTP requests from an external network.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high severity vulnerability with low complexity and low privilege required. The EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS score and the fact that it can be executed over standard HTTP traffic suggest a notable risk to organizations that expose Siebel CRM Deployment to external or untrusted networks. Attackers with network connectivity could exploit the flaw quickly without needing privileged credentials or user interaction.
OpenCVE Enrichment