Impact
The vulnerability is a CWE-284 weakness that allows a low‑privileged attacker with network access over HTTPS to compromise the Siebel CRM Deployment component, enabling a takeover of the system. This results in complete loss of confidentiality, integrity and availability, effectively granting remote control of the application server.
Affected Systems
Oracle Siebel CRM Deployment versions from 17.0 up to 26.7 are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that exploitation is currently unlikely, but the presence of this flaw still poses a serious risk because a successful attack would provide complete takeover. This vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network based over HTTPS, and the low privilege requirement means that a threat actor only needs a non‑privileged account or unauthenticated access to trigger the exploit.
OpenCVE Enrichment