Impact
A vulnerability in Oracle Siebel CRM Deployment’s Server Infrastructure component permits an attacker without authentication to alter or delete critical data, or obtain full access to all data managed by the deployment. The weakness arises from authentication bypass, enabling creation, deletion, or modification of data objects. This leads to severe confidentiality and integrity breaches, potentially affecting all users who rely on the deployment.
Affected Systems
Oracle Corporation’s Siebel CRM Deployment product, versions 17.0 through 26.7, is impacted. The vulnerability is specifically tied to the Server Infrastructure component that processes HTTP traffic.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates a high‑severity weakness. The EPSS score of less than 1% suggests the probability of exploitation is low at this time, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, because an unauthenticated attacker can reach the affected systems via standard HTTP networking, the opportunity for disruption remains. The likely attack vector is an unauthenticated HTTP request directed at the Siebel CRM Deployment’s exposed interfaces, enabling the attacker to inject requests that lead to unauthorized data manipulation.
OpenCVE Enrichment