Impact
This vulnerability allows an attacker who has a low-privilege logon to the infrastructure where Oracle Siebel CRM Deployment runs to create, delete, or modify any data accessible to the deployment. The flaw is a local privilege escalation that removes access controls, enabling unauthorized access or manipulation of all data handled by the deployment. Per the CVSS v3.1 metric, the impact score of 7.1 reflects a high confidentiality and integrity loss with no denial of service effect.
Affected Systems
Oracle Siebel CRM Deployment versions 17.0 through 26.7 are affected. The flaw resides in the Server Infrastructure component of the deployment product and applies to all installations within that version range.
Risk and Exploitability
The CVSS base score of 7.1 denotes a high‑severity risk. The EPSS score is below 1 %, indicating a very low probability of real‑world exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation campaigns. Attackers must have local, low‑privilege access on the host running Siebel CRM Deployment, so the threat is limited to compromised infrastructure but once achieved it grants the attacker unrestricted data access.
OpenCVE Enrichment