Impact
The vulnerability exists in the Open UI component of Oracle Siebel CRM End User and allows an unauthenticated attacker, who can reach the system over the network via SOAP, to create, delete, or modify critical data. The flaw also permits unrestricted access to all data that would normally be available to Siebel users. With a CVSS 3.1 base score of 9.1, the impact includes high confidentiality and integrity damage, and the weakness is reflected by CWE-287 and CWE-306.
Affected Systems
Affected systems are Oracle Siebel CRM End User releases 17.0 through 26.7. Any deployed instance within this version range is vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely but still possible. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by sending crafted SOAP requests without prior authentication, so the attack vector is purely remote over the network.
OpenCVE Enrichment