Impact
This vulnerability exists in the Open UI component of the Siebel CRM End User application. A low‑privileged attacker who can reach the system over HTTP can exploit a flaw that requires a second user’s interaction to execute. Successfully exploiting the flaw grants the attacker the ability to create, delete, or alter critical data and, in the worst case, gain complete access to all data that the application exposes. The weakness effectively bypasses existing access controls and, due to a scope change, can affect other connected Siebel products.
Affected Systems
Versions 17.0 through 26.7 of Oracle’s Siebel CRM End User are affected. The vulnerability may also have repercussions for other Siebel components that interact with the End User module, given the documented scope change.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.7 signals high severity, with significant confidentiality and integrity impacts. An EPSS score of less than 1 % indicates that, while exploitation is theoretically feasible, it is presently unlikely to be observed in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network access via HTTP, low privileges, and a second user’s cooperation to trigger the exploit, but once activated the attacker can inflict serious data manipulation or disclosure.
OpenCVE Enrichment