Impact
Easily exploitable vulnerability in Oracle Siebel CRM's Order Management component (a CWE-284 Broken Access Control flaw) allows a low‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data and grants the attacker full access to all order‑management data available through the system.
Affected Systems
Vulnerable versions of Oracle Siebel Apps – Customer Order Management from 17.0 through 26.7 are affected. The impact extends beyond a single product, potentially affecting additional Siebel applications through altered access scopes.
Risk and Exploitability
The base CVSS score of 8.7 indicates high severity, and the EPSS score of less than 1 % shows a very low probability of exploitation. The vulnerability is network‑based, requiring HTTP access, and notes that some human interaction from another user is necessary. It is not currently listed in the CISA KEV catalog. Because the vector requires no privileged access or complex conditions, the risk is significant for exposed environments but mitigated by limited exploitation likelihood.
OpenCVE Enrichment