Impact
The vulnerability resides in the Server Infrastructure component of Oracle Siebel CRM Deployment, allowing an attacker with low privileges and network access over HTTP to exploit the system. A successful exploitation gives the attacker full control over the Siebel CRM Deployment instance, compromising the confidentiality, integrity, and availability of the application. The CVSS 3.1 vector indicates a network attack, low attack complexity, low privilege requirement, and no user interaction.
Affected Systems
Oracle Siebel CRM Deployment versions 17.0 through 26.7 are impacted, as specified by the vendor.
Risk and Exploitability
The CVSS base score of 8.8 signals a high‑impact risk, and the EPSS score of less than 1% indicates a very low but nonzero probability of exploitation. The vulnerability is not on the CISA KEV list, meaning there are no current publicly disclosed exploit campaigns. Nevertheless, because the attack vector is simple network‑based HTTP access and only requires low privileges, the risk to organizations that host the affected versions remains high.
OpenCVE Enrichment