Impact
An unauthenticated attacker who can reach the Siebel CRM End User service via HTTP can exploit a flaw in the Reports component. The vulnerability allows the attacker to read all data that the end‑user application can access, leading to a complete compromise of the confidentiality of critical information stored in the system. The weakness manifests as a lack of proper access control on report generation, enabling arbitrary data retrieval without authentication. This results in a high‑secrecy breach, as described by the CVSS 3.1 vector.
Affected Systems
Oracle Siebel CRM End User, versions 17.0 through 26.7 inclusive, are affected. The vulnerability is present in the Reports component of the product.
Risk and Exploitability
The CVSS Base Score of 7.5 indicates a high impact on confidentiality. The EPSS score is below 1 %, suggesting a low probability of exploitation at the time of analysis, yet the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely an unauthenticated, network‑based exploit over HTTP, given the described conditions. An attacker does not need any privileged credentials and can gain full read access to the data exposed by the component.
OpenCVE Enrichment