Impact
A vulnerability exists in the Integration – Scripting component of Oracle Siebel CRM that allows an attacker with low privileges and network access via HTTP to cause repeated crashes and to perform unauthorized update, insert, delete or read operations on data accessible to the application. The flaw can compromise both the confidentiality and integrity of data and disrupt service availability through a complete denial‑of‑service condition. The core weakness is an improper access control that permits the attacker to bypass normal authorization checks and manipulate the underlying data store or application state.
Affected Systems
The affected product is Oracle Siebel CRM Development, specifically versions 17.0 through 26.7. Any deployment of these versions over an HTTP interface is susceptible to the flaw.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity with medium complexity and low privileges needed. The EPSS score of less than 1% suggests that exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog, but the impact could be significant in environments where Siebel CRM contains sensitive customer data. The attack vector is via HTTP network access and requires the attacker to trigger a vulnerable integration script, which can be done remotely without user interaction or UI.
OpenCVE Enrichment