Impact
A flaw in the Server Infrastructure component of Oracle Siebel CRM Deployment allows an unauthenticated attacker with network access over HTTP to create, delete, or modify critical data. The bug was scored CVSS 9.1 with high confidentiality and integrity impact, and the CVSS vector indicates that no user interaction or privileges are required for exploitation.
Affected Systems
Oracle Siebel CRM Deployment versions 17.0 through 26.7 are affected. The vulnerability exists in the Siebel CRM Deployment product and is specific to the Server Infrastructure component.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability at present. However, the high CVSS score and the fact that an unauthenticated network attacker can gain full control over deployment data create a significant risk. The attack vector is via HTTP and requires no authentication, so any host exposed to the network could be compromised if the patch is not applied.
OpenCVE Enrichment