Impact
The Siebel CRM Deployment product contains a vulnerability that lets a low‑privileged user with a logged‑on identity on the infrastructure compromise the deployment. The weakness arises from improper access control (CWE-269). Successful exploitation can lead to total takeover, resulting in loss of confidentiality, integrity and availability, as reflected in the CVSS 3.1 Base Score of 7.8.
Affected Systems
Affected vendors and products include Oracle Corporation’s Siebel CRM Deployment. The vulnerability is present in versions 17.0 through 26.7. No further sub‑version detail is provided.
Risk and Exploitability
The CVSS score of 7.8 indicates high impact, while the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. It is exploitable locally with low privileges and no user interaction, meaning that an attacker with local logon to the infrastructure can quickly take over the Siebel CRM Deployment.
OpenCVE Enrichment