Impact
The vulnerability is a SQL injection flaw within the Migration component of Oracle Siebel CRM Deployment. An attacker with low privileged access and network connectivity can send crafted SQL input that is not properly sanitized, allowing arbitrary SQL statements to be executed. Successful exploitation results in a full takeover of the application, compromising confidentiality, integrity, and availability. The weakness corresponds to CWE-89, an SQL injection flaw.
Affected Systems
Oracle’s Siebel CRM Deployment product is affected across versions 17.0 through 26.7. The vulnerability is present in the Migration component of these releases.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high severity with full impact on confidentiality, integrity, and availability. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The description indicates the issue resides in the Migration component, which is exposed via network-accessible interfaces. Based on the description, it is inferred that an attacker would send crafted SQL input to this component, causing arbitrary SQL execution and takeover.
OpenCVE Enrichment