Impact
The vulnerability arises within the Open UI component of Oracle Siebel CRM End User and permits an unauthenticated attacker with network access over HTTP to bypass authentication mechanisms. This flaw enables the attacker to read or manipulate critical data, gain full access to all data exposed by the system, or induce a partial denial of service, affecting confidentiality, integrity, and availability as reflected in the high CVSS score.
Affected Systems
Affected customers use Oracle Siebel CRM End User in versions ranging from 17.0 through 26.7. Vendors should verify that any deployments of these versions have not been patched or otherwise mitigated. No specific build numbers are referenced beyond this range.
Risk and Exploitability
The CVSS 3.1 base score of 8.6 indicates a high severity. The EPSS score is listed as less than 1%, which suggests a very low current exploitation probability, but that does not eliminate the risk. The vulnerability is not yet listed in the CISA KEV catalog, though its potential for widespread unauthorized access makes it a significant asset to adversaries. Attackers could target exposed HTTP endpoints to exploit the flaw without authentication or UI interaction, achieving breach or service disruption.
OpenCVE Enrichment