Impact
The vulnerability resides in the Configuration Tools component of Oracle Siebel CRM Development and permits a low‑privileged attacker with network access to exploit a SQL‑related flaw, resulting in full compromise of the application. This impact spans confidentiality, integrity, and availability as reflected in the CVSS score of 7.5. The weakness is a Broken Access Control flaw, identified as CWE-284, and the description indicates that the exploitation can lead to takeover of the Siebel CRM Development environment.
Affected Systems
Oracle Siebel CRM Development versions 17.0 through 26.7 are affected, specifically the Configuration Tools component. Low‑privileged users on the network can reach the vulnerable SQL interface.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity, yet the EPSS score of less than 1% suggests that exploitation opportunities are currently rare. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. The likely attack vector is via a remote SQL interface that the attacker can reach over the network, and the success of the attack requires only low privileges, elevating the risk for systems with inadequate access control.
OpenCVE Enrichment