Impact
This vulnerability exists in the Server Infrastructure component of Oracle Siebel CRM Deployment, allowing a low‑privileged attacker who can reach the physical communication segment attached to the hardware to compromise the deployment. An attacker can obtain unauthorized access to critical data or all data available through the deployment, and can also force the system to hang or repeatedly crash, resulting in a complete denial‑of‑service.
Affected Systems
Affected are Oracle Siebel CRM Deployment versions 17.0 through 26.7, as identified by the vendor’s CNA.
Risk and Exploitability
The CVSS score of 7.3 indicates significant risk, while the EPSS score of less than 1% suggests current exploitation likelihood is low but not negligible, particularly for systems exposed to the adjacent network. The vulnerability is not listed in CISA’s KEV catalog, yet the local nature of the attack and low privilege requirement mean that exploitation remains feasible within an organization’s internal or physically adjacent network.
OpenCVE Enrichment