Impact
The vulnerability exists in the Siebel Apps – Marketing component of Oracle Siebel CRM. It permits a high privileged attacker with network access over HTTP to compromise the application, resulting in full takeover of the Marketing deployment. The weakness is identified as incorrect access control (CWE‑284), allowing attackers to execute actions with the same privileges as the application process. The impacts include loss of confidentiality, integrity, and availability for all Marketing data and functions.
Affected Systems
Oracle Corporation’s Siebel Apps – Marketing product, versions 17.0 through 26.7, is affected. The attack can be carried out on any installation that receives HTTP requests and has the vulnerable Marketing component deployed.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates a high severity attack that can be executed remotely with low effort and requires high privileges. The EPSS score of less than 1% shows a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. However, the potential for full application takeover and the network‑exposed attack surface make it a high priority. The likely attack vector is a remote HTTP request that abuses the flawed access control to perform privileged actions.
OpenCVE Enrichment