Impact
A flaw in the Helpdesk/Training component of Oracle Siebel Apps - Self Service permits a low-privileged attacker who can reach the application via HTTP to assume full control of the system. The vulnerability, classified as CWE-269, allows compromise of confidentiality, integrity, and availability with a single successful request.
Affected Systems
Oracle Corporation’s Siebel Apps - Self Service is affected. Versions spanning 17.0 up to and including 26.7 contain the vulnerable Helpdesk/Training module. No newer version or patch was indicated in the provided data, so all instances within that range remain at risk until a vendor resolution is applied.
Risk and Exploitability
With a CVSS 3.1 base score of 8.8 the vulnerability is high severity. The EPSS score is less than 1%, indicating a low probability of exploitation at present, and the flaw is not catalogued in CISA's KEV. The vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) shows exploitation requires only network access over HTTP, low attack complexity, and low privileges, with no user interaction. An attacker satisfying those conditions can gain complete control of the Self Service instance, exposing all stored customer data and internal processes.
OpenCVE Enrichment