Impact
This vulnerability is an authentication bypass (CWE‑284) that permits an unauthenticated attacker with network access over HTTP to gain entry to the Oracle Siebel CRM Financial Services Financial Accounts component. Successful exploitation can lead to unauthorized exposure of sensitive data and can also trigger application hangs or repeatable crashes, causing a loss of availability.
Affected Systems
The affected product is Oracle Siebel CRM Financial Services, specifically the Financial Accounts module, in all supported releases from version 17.0 through 26.7 inclusive. These versions are deployed in environments that expose the application over HTTP.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates a high impact on confidentiality and availability, while the EPSS score of less than 1% suggests a low predicted exploitation frequency. Nevertheless, because the flaw is directly reachable over HTTP and requires no authentication, the risk remains significant. The vulnerability is not listed in CISA KEV, but the lack of mitigate controls in the default configuration means that, if discovered, an attacker could readily compromise data and disrupt services.
OpenCVE Enrichment