Impact
The vulnerability resides in the server infrastructure component of Oracle Siebel CRM Deployment and permits an unauthenticated attacker with TCP network access to compromise the system. The flaw enables full control, resulting in loss of confidentiality, integrity, and availability of data and application functions, as reflected in the CVSS v3.1 vector with high complexity and no required privileges. Successful exploitation can lead to a complete takeover of the deployment.
Affected Systems
Oracle Corporation’s Siebel CRM Deployment product is affected, specifically versions 17.0 through 26.7 of the software. Systems running any of these revisions are at risk if not updated.
Risk and Exploitability
The base CVSS score of 8.1 indicates high severity, but the current EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers require only network connectivity to the vulnerable service, no special credentials or user interaction, and are able to forge requests to the TCP port that hosts the server infrastructure.
OpenCVE Enrichment