Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

A flaw in Oracle Siebel CRM Deployment’s Server Infrastructure component allows an unauthenticated attacker with network access over HTTP to exploit the service. The vulnerability causes resource exhaustion, leading the deployment to hang or repeatedly crash, which results in a complete denial of service. The weakness is identified as CWE-400, indicating an unbounded resource consumption flaw.

Affected Systems

Oracle Corporation’s Siebel CRM Deployment is affected across all builds from version 17.0 through 26.7. Versions prior to 17.0 or beyond 26.7 are not listed as vulnerable. The vulnerability impacts only the Server Infrastructure component accessed via HTTP.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.5 reflects a high severity due to availability impacts. The EPSS score of less than 1% suggests that exploitation in the wild remains rare. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the denial of service by sending repeated HTTP requests that exhaust server resources without requiring authentication. Because the flaw affects the entire deployment, it poses a significant operational risk for organizations relying on Siebel CRM.

Generated by OpenCVE AI on September 18, 2026 at 19:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch or upgrade to a version newer than 26.7 as advertised in Oracle’s security advisory https://www.oracle.com/security-alerts/cspusep2026.html.
  • Restrict HTTP access to the Siebel CRM Deployment to trusted internal networks or specific IP ranges until the patch is deployed.
  • Implement request limiting or rate‑limiting controls on the HTTP entry points to the Server Infrastructure component to mitigate potential resource exhaustion.
  • Monitor system metrics and application logs for abnormal CPU or memory spikes that could indicate an ongoing exploitation attempt.

Generated by OpenCVE AI on September 18, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Siebel CRM Deployment Resource Exhaustion Causing Service Denial

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Siebel CRM Deployment Resource Exhaustion Causing Service Denial

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Siebel Crm Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:54.346Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83183

cve-icon Vulnrichment

Updated: 2026-09-15T23:13:21.886Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:29.470

Modified: 2026-09-21T16:50:49.440

Link: CVE-2026-83183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:15:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption