Impact
An attacker with low privileged access and network connectivity can exploit a SQL injection flaw in the Migration component of Oracle Siebel CRM Deployment. Successful exploitation results in a full takeover of the application, compromising confidentiality, integrity, and availability. The weakness corresponds to CWE‑89 and CWE‑20.
Affected Systems
Oracle’s Siebel CRM Deployment product is affected across versions 17.0 through 26.7. The vulnerability is present in the Migration component of these releases.
Risk and Exploitability
The CVSS v3.1 base score is 8.8, indicating high severity with full impact on confidentiality, integrity and availability. The EPSS score is below 1 %, suggesting low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the attack requires only low privileges and remote network access, making it attractive to attackers who can target the migration interface or database backend. The exploitation path involves sending crafted SQL input to the Migration API, which is not adequately sanitized, leading to arbitrary code execution and takeover.
OpenCVE Enrichment