Impact
The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment. A high‑privileged attacker who can reach the system over HTTP can exploit this flaw to gain complete control of the deployment, potentially compromising confidentiality, integrity, and availability. The flaw is a privilege escalation weakness that enables takeover of the deployment environment and may affect additional products due to scope change.
Affected Systems
Oracle Siebel CRM Deployment, versions 17.0 through 26.7, are affected. All supported releases in this range are vulnerable whenever the Server Infrastructure component is exposed to network traffic.
Risk and Exploitability
CVSS 3.1 base score of 9.1 classifies the issue as critical. EPSS < 1% indicates a low current exploitation probability, but the lack of KEV listing does not reduce overall risk. Exploitation requires network access via HTTP and a high‑privilege account, after which the attacker can fully compromise the system. The likely attack vector is over HTTP traffic to the deployment server.
OpenCVE Enrichment