Impact
The vulnerability exists in the Open UI component of Oracle Siebel CRM End User, permitting an unauthenticated attacker with network access via HTTP to compromise the entire system. Successful exploitation results in a full takeover, leading to complete loss of confidentiality, integrity, and availability. The root weakness is inadequate enforcement of authentication and access controls, represented by CWE-269.
Affected Systems
Oracle Siebel CRM End User, versions 17.0 through 26.7, is affected. Any deployment still employing the legacy Open UI interface is vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 signals a high severity flaw, while the EPSS score of less than 1% indicates a low probability of current exploitation. It is not listed in the CISA KEV catalog. Attackers need only network connectivity to the exposed HTTP service and no authentication to trigger the exploit, though the high access complexity suggests that technical barriers exist. Once the flaw is exploited, the impact is total takeover of the Siebel CRM End User instance.
OpenCVE Enrichment