Impact
The flaw lies in the Workflow component of Oracle Siebel CRM Development, enabling a low-privileged attacker with network access over HTTP to execute arbitrary code. Because the vulnerability is classified under improper access control (CWE‑284), the attacker can bypass normal authentication checks and gain full control, thereby compromising confidentiality, integrity, and availability of the application.
Affected Systems
Oracle Corporation’s Siebel CRM Development product, specifically versions 17.0 through 26.7, is impacted. The vulnerability targets the Workflow component and is exploitable via the HTTP interface exposed by these deployments.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 reflects high severity, while the EPSS score is less than 1 percent, indicating a low exploitation probability at present. Nevertheless, the vulnerability is easily exploitable from a remote network connection, and it is not listed in the CISA KEV catalog. A low‑privileged attacker who can reach the HTTP endpoints can take over the entire application, posing significant risk even with the low EPSS.
OpenCVE Enrichment