Impact
A flaw in Oracle Siebel CRM Development’s Workspaces component allows an unauthenticated attacker gain full access to all data exposed by the application. The vulnerability also enables the The primary impact is a high confidentiality loss with the potential for availability degradation, as reflected in the CVSS 3.1 base score of 8.2.
Affected Systems
Oracle Siebel CRM Development versions 17.0 through 26.7 are affected. The weakness exists in the Workspaces component of the product, which is typically accessible over standard HTTP ports to external users.
Risk and Exploitability
The CVSS score indicates a high severity vulnerability, but the EPSS score is less than 1%, suggesting that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a simple HTTP request to the vulnerable Workspaces endpoint, once exploited, an attacker can read sensitive data and interrupt services partially, potentially impacting business operations and data confidentiality.
OpenCVE Enrichment