Impact
A flaw in the Integration – Scripting component of Oracle’s Siebel CRM Development allows an attacker with low privileges and network access via HTTP to bypass authentication checks and manipulate data or crash the application. The vulnerability arises from improper access control (CWE‑284) and the possibility for unauthorized updates, inserts, deletes, and reads available through the HTTP interface. Successful exploitation can lead to loss of data integrity, availability through repeated crashes, and partial disclosure of sensitive data.
Affected Systems
Oracle Siebel CRM Development versions 17.0 through 26.7 are affected. The flaw is exposed through any deployment that serves integration scripts over an unprotected HTTP channel.
Risk and Exploitability
The vulnerability has a CVSS score of 7.6, indicating high severity with low complexity and low privileges required. The EPSS score of less than 1 % indicates that exploitation is unlikely but still possible. It is not listed in the CISA KEV catalog. Attackers can remotely trigger the flaw via HTTP without user interaction, making it a straightforward low‑effort, high‑impact attack for networks with open access to the affected server.
OpenCVE Enrichment