Impact
The vulnerability exists in the Server Infrastructure component of Oracle Siebel CRM Deployment. It allows an attacker who is logged into the deployment infrastructure with low-privileged credentials to gain full control over the entire deployment, enabling arbitrary code execution, data tampering, and service disruption. The flaw is a privilege‑management or access‑control weakness, classified as CWE-269, and results in loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Siebel CRM Deployment, versions 17.0 through 26.7, are affected. These releases include the Server Infrastructure component and are accessible to users who can log into the deployment’s host environment. No other variants or supplemental modules are listed as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 indicates high severity, while the EPSS score of less than 1% signals that active exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local, inferred from the CVSS vector AV:L, meaning the attacker must already have a logged‑on session on the host environment with low privileges. Successful exploitation would give the attacker full control over the Siebel CRM Deployment, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment