Impact
This vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment. An attacker with network access via TCP can exploit a flaw that enables the bypass or override of normal access controls, allowing the attacker to elevate privileges and ultimately take full control of the application. Successful exploitation results in complete compromise, impacting confidentiality, integrity, and availability of all data and services managed by the CRM system.
Affected Systems
Affected vendor: Oracle Corporation, product: Siebel CRM Deployment. Versions 17.0 through 26.7 are impacted. The vulnerability is present across all build variants of this product range.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates a high severity with impacts to confidentiality, integrity and availability. The EPSS score of less than 1% suggests that real‑world exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. However, the attack vector is a TCP connection that a remote attacker can establish, so a threat actor could attempt this attack. Once the flaw is exploited the attacker can fully takeover the Siebel CRM Deployment instance.
OpenCVE Enrichment