Impact
The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment and allows a low‑privileged attacker who can log on to the underlying infrastructure to execute code paths that can result in a full takeover of the Siebel CRM Deployment service. Successful exploitation for this vulnerability can lead to complete loss of confidentiality, integrity, and availability of the application, enabling the attacker to control its operation.
Affected Systems
Oracle Siebel CRM Deployment versions 17.0 through 26.7 are affected. Organisations using these releases must confirm their version and plan to apply a vendor‑issued fix if one becomes available.
Risk and Exploitability
The CVSS 3.1 base score of 7.3 indicates substantial impact, while the EPSS of less than 1% suggests that exploitation is unlikely at present but remains possible. The vulnerability is not listed in the CISA KEV catalog. The attack requires local access (AV:L) and human interaction from a user other than the attacker, which implies a moderate to high risk for environments that do not restrict local logon privileges or monitor for suspicious activity.
OpenCVE Enrichment