Impact
The vulnerability in the Open UI component of Oracle Siebel CRM End User is an improper access control flaw (CWE-284). An attacker with low privileges and network access via HTTP can read or modify data that should be restricted, leading to confidentiality and integrity breaches. The flaw allows the attacker to retrieve or alter critical data without proper authentication or authorization, effectively bypassing application security controls.
Affected Systems
Oracle Siebel CRM End User, specifically the Open UI component, is affected. Versions 17.0 through 26.7 contain the flaw and should be considered vulnerable if deployed.
Risk and Exploitability
The CVSS v3.1 score of 7.1 indicates medium‑to‑high severity, impacting confidentiality and integrity. The EPSS score is reported as less than 1 %, suggesting that widespread exploitation is currently low, but the vulnerability is still considered easily exploitable from the network. It is not listed in CISA’s KEV catalog. Exploitation can occur via a remote HTTP request to the Open UI endpoints from an external or internal low‑privileged user without user interaction beyond sending the request.
OpenCVE Enrichment