Impact
Oracle Siebel CRM Deployment is vulnerable to a flaw in its Server Infrastructure component that allows an attacker with low privileges and network access via HTTP to execute arbitrary code and assume full control of the deployment. The flaw corresponds to an unauthorized access weakness, enabling the attacker to elevate privileges and compromise confidentiality, integrity and availability. The reported CVSS score of 8.8 indicates severe impact and the vector shows that no authentication is required beyond low privileged access.
Affected Systems
Oracle Siebel CRM Deployment, versions 17.0 through 26.7, is affected. Installations outside this range are not listed as vulnerable.
Risk and Exploitability
The likelihood of exploitation is currently low, with an EPSS score of less than 1%, and the vulnerability is not tracked in CISA KEV. Nonetheless the high CVSS impact and ease of exploitation via the public HTTP interface mean that a compromised deployment would allow a full data breach and service disruption. Attackers can achieve confidentiality, integrity, and availability compromise once the flaw is used.
OpenCVE Enrichment