Impact
Vulnerability exists in the Life Sciences component of Oracle Siebel CRM, allowing a low‑privileged attacker with local logon on the host that runs the application to compromise the application. Successful exploitation would give the attacker full control of Siebel Apps – Life Sciences, leading to loss of confidentiality, integrity and availability. The issue is characterized by a high impact CVSS 3.1 score of 7.3. The vulnerability also requires human interaction from a person other than the attacker.
Affected Systems
The affected product is Oracle Siebel CRM – Life Sciences. Versions from 17.0 through 26.7 are impacted. No other versions or components are listed in the advisory.
Risk and Exploitability
CVSS base score 7.3 indicates moderately high severity. EPSS is <1 %, suggesting current exploitation likelihood is very low but not impossible. The vulnerability is not listed in CISA KEV. Exploitation requires a user present on the system, local access, and low privileges, but no network attack vector, making it relevant for organizations that allow local user accounts to interact with the application.
OpenCVE Enrichment