Impact
The bug resides in the Server Infrastructure component of the Siebel CRM Deployment product. An unauthenticated attacker who can reach the system over HTTP can exploit the vulnerability to obtain unauthorized access to critical data or to gain full read or modify permissions on all data accessible through the deployment. The impact includes confidentiality breaches and integrity violations, potentially allowing the attacker to insert, modify or delete records.
Affected Systems
Oracle Siebel CRM Deployment versions 17.0 through 26.7 are affected. The product is a platform for managing customer relationships, and all deployments running a version in this range are at risk unless updated.
Risk and Exploitability
The vulnerability was scored 8.2 on CVSS v3.1, indicating high severity. EPSS indicates a probability of exploitation of less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not actively exploited in the wild yet. The attack vector is inferred to be an unauthenticated network request via HTTP; the attacker does not need to authenticate or bypass any authorization controls to exploit the flaw. Given the high confidentiality impact and the availability of a straightforward HTTP request, the risk remains significant for exposed deployments.
OpenCVE Enrichment