Impact
The vulnerability resides in the Workflow component of Oracle Siebel CRM Development, and it permits a low-privileged attacker to gain full control over the application when accessing the system through HTTP. The flaw effectively allows an adversary to execute arbitrary code and thereby compromise confidentiality, integrity and availability of the system. Based on the description, it is inferred that the weakness can be categorized under improper access control and authentication bypass, enabling a remote attacker to perform actions normally restricted to higher-privilege users.
Affected Systems
Oracle Corporation offers the Siebel CRM Development product, versions 17.0 through 26.7, which are affected. The issue specifically targets the Workflow component and affects deployments HTTP interfaces.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 rates this as a high-severity vulnerability, and the EPSS score is below 1%, indicating a relatively. Although the vulnerability is not listed in the CISA KEV catalog, it is easily exploitable via a network connection from outside the protected environment. An attacker with limited privileges can achieve full takeover if the product is reachable over HTTP, making the risk of compromise significant regardless of the low EPSS.
OpenCVE Enrichment