Impact
A flaw in Oracle Siebel Apps – Financial Services allows an unauthenticated attacker to bypass authentication and gain access to the Financial Accounts component via plain HTTP. The vulnerability enables the attacker to read confidential data and, by repeated requests, bring the application to a persistent crash, causing a denial of service. The weakness involved is missing authentication controls (CWE‑306).
Affected Systems
Oracle Siebel CRM Financial Services, specifically the Financial Accounts module, in all supported releases from version 17.0 through 26.7 inclusive. Environments that expose the application over HTTP are directly exposed to attack.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates high confidentiality and availability impact. The EPSS score of less than 1% suggests a low global likelihood of exploitation, yet the vulnerability is reachable over an HTTP endpoint and requires no authentication, keeping the risk significant. The flaw is not listed in the CISA KEV catalog, but based on the description, it is inferred that its lack of protective controls in the default configuration still makes it a serious threat.
OpenCVE Enrichment