Impact
The vulnerability exists in the Server Infrastructure component of Oracle Siebel CRM Deployment. An unauthenticated attacker who can reach the system via HTTP can create, delete, or modify data without providing any credentials. This unauthorized access can result in the loss of confidentiality and integrity of all data accessible through the deployment.
Affected Systems
The affected products are Oracle Siebel CRM Deployment for versions 17.0 through 26.7. Any installation of these versions that exposes the HTTP interface is susceptible to the described flaw.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 indicates a moderate-to-high severity. The EPSS score of less than 1% suggests a low probability that the vulnerability will be exploited in the wild. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a network-based HTTP request from an unauthenticated source, requiring no special privileges or credentials to gain the described capabilities.
OpenCVE Enrichment