Impact
A flaw in Oracle Siebel CRM Deployment’s Server Infrastructure component allows an unauthenticated attacker with network access over HTTP to exploit the service. The vulnerability causes resource exhaustion, leading the deployment to hang or repeatedly crash, which results in a complete denial of service. The weakness is identified as CWE-400, indicating an unbounded resource consumption flaw.
Affected Systems
Oracle Corporation’s Siebel CRM Deployment is affected across all builds from version 17.0 through 26.7. Versions prior to 17.0 or beyond 26.7 are not listed as vulnerable. The vulnerability impacts only the Server Infrastructure component accessed via HTTP.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.5 reflects a high severity due to availability impacts. The EPSS score of less than 1% suggests that exploitation in the wild remains rare. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the denial of service by sending repeated HTTP requests that exhaust server resources without requiring authentication. Because the flaw affects the entire deployment, it poses a significant operational risk for organizations relying on Siebel CRM.
OpenCVE Enrichment