Impact
This vulnerability exists in the Server Infrastructure component of Oracle Siebel CRM Deployment and is fully exploitable by an attacker with low privileges who can reach the system over HTTP. Successful exploitation allows the attacker to gain full control of the Siebel CRM Deployment instance, compromising confidentiality, integrity, and availability. The CVSS 3.1 vector indicates a network attack, low attack complexity, low privileges required, and no user interaction needed.
Affected Systems
Oracle Siebel CRM Deployment, versions 17.0 through 26.7, as listed by the vendor.
Risk and Exploitability
The CVSS base score of 8.8 signals a high‑impact risk, and the EPSS score of less than 1% indicates a very low but nonzero probability of exploitation. The vulnerability is not on the CISA KEV list, meaning there are no current publicly disclosed exploit campaigns. Nevertheless, because the attack vector is simple network‑based HTTP access and only requires low privileges, the risk to organizations that host the affected versions remains high.
OpenCVE Enrichment